<html><head><meta http-equiv="Content-Type" content="text/html charset=windows-1252"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;"><br><div><div>On Mon, 11 Aug 2014, at 12:48 , Kevin Foote <<a href="mailto:kpfoote@uoregon.edu">kpfoote@uoregon.edu</a>> wrote:</div><blockquote type="cite">...<br><br>Is the SP requesting a specific NameID format?<br></blockquote>Included in the original posted question:</div><div>the SP metadata includes:<div><div style="margin: 0px; font-size: 13px; font-family: Monaco; background-color: rgb(255, 250, 194);"> <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat></div><div style="margin: 0px; font-size: 13px; font-family: Monaco; background-color: rgb(255, 250, 194); position: static; z-index: auto;"> <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</NameIDFormat></div></div><div><br></div><blockquote type="cite">Your IdP logs should show what it is choosing for the NameID or something to the effect of "no suitable attribute found for requested nameID format” <br></blockquote>Yes, that’s what the IdP reports; but why wasn’t the TransientId considered? Included in the original posted question:</div><div><div style="margin: 0px; font-size: 11px; font-family: Monaco; background-color: rgb(255, 250, 194);">09:15:25.423 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:527] - Filtering out potential name identifier attributes which can not be encoded by edu.internet2.middleware.shibboleth.common.attribute.encoding.SAML2<span style="color: rgb(255, 250, 194); background-color: rgb(0, 0, 0);">NameID</span>Encoder</div><div style="margin: 0px; font-size: 11px; font-family: Monaco; background-color: rgb(255, 250, 194);">09:15:25.424 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:546] - Removing attribute AWSsessionID, it can not be encoded via edu.internet2.middleware.shibboleth.common.attribute.encoding.SAML2<span style="color: rgb(255, 250, 194); background-color: rgb(0, 0, 0);">NameID</span>Encoder</div><div style="margin: 0px; font-size: 11px; font-family: Monaco; background-color: rgb(255, 250, 194);">09:15:25.424 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:546] - Removing attribute AWSrole, it can not be encoded via edu.internet2.middleware.shibboleth.common.attribute.encoding.SAML2<span style="color: rgb(255, 250, 194); background-color: rgb(0, 0, 0);">NameID</span>Encoder</div><div style="margin: 0px; font-size: 11px; font-family: Monaco; background-color: rgb(255, 250, 194); position: static; z-index: auto;">09:15:25.424 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:504] - No attributes for principal 'dabantz' support encoding into a supported name identifier format for relying party ‘urn:amazon:webservices'</div><br><blockquote type="cite"><div><br></div>Are you specifically blocking the release of your attribute in another filter?<br></blockquote>The reverse is intended: included in the original posted question:</div><div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194); font-size: 10px;"> <AttributeFilterPolicy id="release<span style="color: rgb(255, 250, 194); background-color: rgb(0, 0, 0);">Transient</span>IdToAnyone"></div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194); font-size: 10px;"> <PolicyRequirementRule xsi:type="basic:ANY" /></div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194); font-size: 10px;"> <AttributeRule attributeID="transientId"></div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194); font-size: 10px;"> <PermitValueRule xsi:type="basic:ANY" /></div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194); font-size: 10px;"> </AttributeRule></div><div style="margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194); font-size: 10px;"> </AttributeFilterPolicy></div><blockquote type="cite"><br><br>--------<br>thanks<br> kevin.foote<br><br></blockquote></div><br></body></html>