<html><body><div style="color:#000; background-color:#fff; font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, Sans-Serif;font-size:12pt"><div><span>Hi,</span></div><div style="background-color: transparent;"><span> I have set the log level to DEBUG. I checked my LDAP directory and can see user has value for "mail" attribute.</span></div><div style="background-color: transparent;"><span>I have attached the idp-process.log, attribute-resolver.xml and attribute-filter.xml.</span></div><div style="background-color: transparent;"><br clear="none"></div><div style="background-color: transparent;"><span>Let me know if i am missing something here.</span></div><div style="background-color: transparent;"><br clear="none"></div><div style="background-color: transparent;"><span>Thanks,</span></div><div></div><div></div><div><span></span></div><div style="background-color: transparent;">Vasu</div><div><br></div> <div style="font-family:
HelveticaNeue, 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 12pt;"> <div style="font-family: 'times new roman', 'new york', times, serif; font-size: 12pt;"> <div dir="ltr"> <hr size="1"> <font size="2" face="Arial"> <b><span style="font-weight:bold;">From:</span></b> Kevin P. Foote <kpfoote@iup.edu><br> <b><span style="font-weight: bold;">To:</span></b> Shib Users <users@shibboleth.net> <br> <b><span style="font-weight: bold;">Sent:</span></b> Thursday, 21 November 2013 9:49 PM<br> <b><span style="font-weight: bold;">Subject:</span></b> Re: IdP: Returning emailAddress as NameId in SAMLResponse Assertion<br> </font> </div> <div class="y_msg_container"><br><br clear="none"><br clear="none"><br clear="none">On Thu, 21 Nov 2013, vyal2k wrote:<br clear="none"><br clear="none">> Thanks. <br clear="none">> I commented out the "AttributeFilterPolicy" for "transientId" AttributeRule and now there is no
response from IdP and i see the following in idp-process.log:<br clear="none">><br clear="none">> 21:34:27.889 - WARN [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:491] - No attribute of principal 'user1' can be encoded in to a NameIdentifier of required format 'urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress' for relying party '<a shape="rect" href="https://inw00003973:8443'/" target="_blank">https://inw00003973:8443'</a><br clear="none"><br clear="none">So now you are back to getting your attribute-resolver fixed so one of<br clear="none">your attributes is properly encoded to the format you are trying to<br clear="none">deliver.<br clear="none"><br clear="none">I'm guessing that the attribute you are trying to encode to the specific<br clear="none">format is not being populated for the user properly and therefor can not<br clear="none">be encoded correctly... Again just guessing.<br clear="none"><br
clear="none">You should also turn up logging to the level of "Debug" when testing<br clear="none">this stuff so many of these errors will bubble up so you can see them.<div class="yqt4174566271" id="yqtfd52643"><br clear="none"><br clear="none"><br clear="none">------<br clear="none">thanks<br clear="none"> kevin.foote</div><br><div class="yqt4174566271" id="yqtfd56559">--<br clear="none">To unsubscribe from this list send an email to <a shape="rect" ymailto="mailto:users-unsubscribe@shibboleth.net" href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a></div><br><br></div> </div> </div> </div></body></html>