<html><head><meta http-equiv="Content-Type" content="text/html charset=windows-1252"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;">Thank you Peter, Scott and Kevin.<div><br></div><div>The SAML authentication request does refer to a NameID as you suggest.</div><div><br></div><div><div style="margin: 0px; font-size: 10px; font-family: Monaco;">14:20:38.500 - DEBUG [PROTOCOL_MESSAGE:113] -</div><div style="margin: 0px; font-size: 10px; font-family: Monaco;"><?xml version="1.0" encoding="UTF-8"?><ns0:AuthnRequest xmlns:ns0="urn:oasis:names:tc:SAML:2.0:protocol" AssertionConsumerServiceURL="<a href="https://www.fuzemeeting.com/fuze/saml_verify/alaskaedu">https://www.fuzemeeting.com/fuze/saml_verify/alaskaedu</a>" Destination="<a href="https://idp.alaska.edu/idp/profile/SAML2/Redirect/SSO">https://idp.alaska.edu/idp/profile/SAML2/Redirect/SSO</a>" ID="id-f6ea64e95fbae2638f2c975fa6b29809" IssueInstant="2013-11-12T23:20:38Z" ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" ProviderName="Test FB SAML" Version="2.0" xmlns:ns1="urn:oasis:names:tc:SAML:2.0:assertion"></div><div style="margin: 0px; font-size: 10px; font-family: Monaco;"> <ns1:Issuer Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity"><a href="http://www.fuzemeeting.com">www.fuzemeeting.com</a></ns1:Issuer></div><div style="margin: 0px; font-size: 10px; font-family: Monaco;"> <<u>ns0:NameIDPolicy AllowCreate="true" Format="urn:oasis:names:tc:SAML:2.0:nameid-format:<span style="background-color: #e6e600">transient</span>"/</u>></div><div style="margin: 0px; font-size: 10px; font-family: Monaco;"></ns0:AuthnRequest></div></div><div><br></div><div>And while I remembered that we released transientId to anyone, upon closer</div><div>examination I see that portion of the release policy was commented out as</div><div>part of the attempt to integrate with GAE.</div><div><br></div><div>So I added an explicit release of transientId, which seems to have the appropriate</div><div>encoder:</div><div><br></div><div><div style="margin: 0px; font-size: 10px; font-family: Monaco;">attribute-resolver.xml fragment:</div><div style="margin: 0px; font-size: 10px; font-family: Monaco; min-height: 14px;"><br></div><div style="margin: 0px; font-size: 10px; font-family: Monaco; color: rgb(195, 55, 32);"><span style="color: #000000"> </span><span style="color: #34bbc7"><</span><span style="color: #d53bd3">resolver</span><span style="color: #5330e1">:</span><span style="color: #34bbc7">AttributeDefinition </span><span style="color: #34bd26">id</span><span style="color: #000000">=</span>"<span style="color: #991200; background-color: #e6e600">transientId</span>"<span style="color: #34bbc7"> </span><span style="color: #34bd26">xsi</span><span style="color: #5330e1">:</span><span style="color: #34bd26">type</span><span style="color: #000000">=</span>"TransientId"<span style="color: #34bbc7"> </span><span style="color: #34bd26">xmlns</span><span style="color: #000000">=</span>"urn:mace:shibboleth:2.0:resolver:ad"<span style="color: #34bbc7">></span></div><div style="margin: 0px; font-size: 10px; font-family: Monaco; color: rgb(195, 55, 32);"><span style="color: #000000"> </span><span style="color: #34bbc7"><</span><span style="color: #d53bd3">resolver</span><span style="color: #5330e1">:</span><span style="color: #34bbc7">AttributeEncoder </span><span style="color: #34bd26">xsi</span><span style="color: #5330e1">:</span><span style="color: #34bd26">type</span><span style="color: #000000">=</span>"SAML1StringNameIdentifier"<span style="color: #34bbc7"> </span><span style="color: #34bd26">xmlns</span><span style="color: #000000">=</span>"urn:mace:shibboleth:2.0:attribute:encoder"</div><div style="margin: 0px; font-size: 10px; font-family: Monaco; color: rgb(195, 55, 32);"><span style="color: #34bbc7"> </span><span style="color: #34bd26">nameFormat</span><span style="color: #000000">=</span>"urn:mace:shibboleth:1.0:nameIdentifier"<span style="color: #34bbc7"> /></span></div><div style="margin: 0px; font-size: 10px; font-family: Monaco; min-height: 14px;"><br></div><div style="margin: 0px; font-size: 10px; font-family: Monaco; color: rgb(195, 55, 32);"><span style="color: #000000"> </span><span style="text-decoration: underline ; color: #34bbc7"><</span><span style="text-decoration: underline ; color: #d53bd3">resolver</span><span style="text-decoration: underline ; color: #5330e1">:</span><span style="text-decoration: underline ; color: #34bbc7">AttributeEncoder </span><span style="text-decoration: underline ; color: #34bd26">xsi</span><span style="text-decoration: underline ; color: #5330e1">:</span><span style="text-decoration: underline ; color: #34bd26">type</span><span style="text-decoration: underline ; color: #000000">=</span><span style="text-decoration: underline">"SAML2StringNameID"</span><span style="text-decoration: underline ; color: #34bbc7"> </span><span style="text-decoration: underline ; color: #34bd26">xmlns</span><span style="text-decoration: underline ; color: #000000">=</span><span style="text-decoration: underline">"urn:mace:shibboleth:2.0:attribute:encoder"</span></div><div style="margin: 0px; font-size: 10px; font-family: Monaco; color: rgb(195, 55, 32);"><span style="text-decoration: underline ; color: #34bbc7"> </span><span style="text-decoration: underline ; color: #34bd26">nameFormat</span><span style="text-decoration: underline ; color: #000000">=</span><span style="text-decoration: underline">"urn:oasis:names:tc:SAML:2.0:nameid-format:transient"</span><span style="text-decoration: underline ; color: #34bbc7"> /></span></div><div style="margin: 0px; font-size: 10px; font-family: Monaco; min-height: 14px;"><br></div><div style="margin: 0px; font-size: 10px; font-family: Monaco; color: rgb(52, 187, 199);"><span style="color: #000000"> </span></<span style="color: #d53bd3">resolver</span><span style="color: #5330e1">:</span>AttributeDefinition></div></div><div><br></div><div>While a value of transientId is created and among those filtered for release to the appropriate end point,</div><div>it is not included in the SAML assertion, with the following debug message:</div><div><br></div><div><div style="margin: 0px; font-size: 10px; font-family: Monaco;">idp-process.log fragment:</div><div style="margin: 0px; font-size: 10px; font-family: Monaco; min-height: 14px;"><br></div><div style="margin: 0px; font-size: 10px; font-family: Monaco;"><div style="margin: 0px;">14:20:48.628 - DEBUG [edu.internet2.middleware.shibboleth.common.attribute.filtering.provider.ShibbolethAttributeFilteringEngine:114] - Filtered attributes for principal dabantz. The following attributes remain: [surname, transientId, email, eduPersonPrincipalName, givenName]</div><div style="margin: 0px;">14:20:48.628 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.AbstractSAML2ProfileHandler:501] - Creating attribute statement in response to SAML request 'id-f6ea64e95fbae2638f2c975fa6b29809' from relying party '<a href="http://www.fuzemeeting.com">www.fuzemeeting.com</a>'</div><div style="margin: 0px;">14:20:48.628 - DEBUG [edu.internet2.middleware.shibboleth.common.attribute.provider.ShibbolethSAML2AttributeAuthority:215] - Encoded attribute surname with encoder of type edu.internet2.middleware.shibboleth.common.attribute.encoding.provider.SAML2StringAttributeEncoder</div><div style="margin: 0px;">14:20:48.628 - DEBUG [edu.internet2.middleware.shibboleth.common.attribute.provider.ShibbolethSAML2AttributeAuthority:226] - Attribute <span style="background-color: #e6e600">transientId was not encoded</span> because no SAML2AttributeEncoder was attached to it.</div><div style="margin: 0px;">14:20:48.629 - DEBUG [edu.internet2.middleware.shibboleth.common.attribute.provider.ShibbolethSAML2AttributeAuthority:215] - Encoded attribute email with encoder of type edu.internet2.middleware.shibboleth.common.attribute.encoding.provider.SAML2StringAttributeEncoder</div><div><br></div></div></div><div>What is the incompatibility between my resolver definition and the attribute encoder?</div><div><br></div><div><div><div>On Tue, 12 Nov 2013, at 11:29 , Peter Schober <<a href="mailto:peter.schober@univie.ac.at">peter.schober@univie.ac.at</a>> wrote:</div><br class="Apple-interchange-newline"><blockquote type="cite">* David Bantz <<a href="mailto:dabantz@alaska.edu">dabantz@alaska.edu</a>> [2013-11-12 21:10]:<br><blockquote type="cite">I see the warning that no attribute can be encoded as NameIdentifier<br>in “required” format; “good” responses to other SPs have messages<br>that no attribute can be encoded as NameIdentifier in “supported”<br>format (not labeled warning).<br>I suspect this should tell me something useful, but admit I don’t<br>understand what it’s telling me.<br></blockquote><br>Have a look at the authentication request, which should also be in the<br>DEBUG log (or grab a new one frmo the browser, easiest with Firefox's<br>SAML tracer extension). Seems the SP requests a NameID of format<br>"urn:oasis:names:tc:SAML:2.0:nameid-format:transient"<br>(which btw does not make too much sense, cf. a very recent thread<br>about that).<br><br><blockquote type="cite"><saml2p:StatusMessage>Required NameID format not supported</saml2p:StatusMessage><br></blockquote><br>Did you block release of the default attribute "transientId" in your<br>filter (or change the resolver wrt that)? Even a newly installed IDP<br>will be able to supply NameIDs of that format so you must have<br>changed/disabled that.<br>-peter<br><br><br>--<br>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a></blockquote></div><br></div></body></html>