<div dir="ltr">So you are talking about something like:<div> nameIDFormatPrecedence="urn:oasis:names:tc:SAML:2.0:nameid-format:persistent"<br></div><div>But what if I have two nameid's encoded as persistent (like ImmutableID and eduPersonTargetedID") and my filter releases them both, which one wins? Or is that something i must control with the filter, making sure i'm not releasing two nameid's of same encoded format?<br>
</div><div><br></div><div>-Rob</div><div><br></div></div><div class="gmail_extra"><br><br><div class="gmail_quote">On Wed, Aug 27, 2014 at 10:00 AM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div class="">On 8/27/14, 9:54 AM, "Rob Gorrell" <<a href="mailto:rwgorrel@uncg.edu">rwgorrel@uncg.edu</a>> wrote:<br>
<br>
>gotcha, i'm learning something here. so since I'm after releasing a<br>
>custom nameid to this SP, it would look like:<br>
><br>
><br>
> <rp:RelyingParty id="urn:federation:MicrosoftOnline"<br>
>provider="<a href="https://prdidp.uncg.edu/idp/shibboleth" target="_blank">https://prdidp.uncg.edu/idp/shibboleth</a>"<br>
> defaultSigningCredentialRef="IdPCredential"<br>
>nameIDFormatPrecedence="ImmutableID"><br>
<br>
</div>No. You specify the SAML format you want, has nothing to do with the<br>
underlying attribute. You need something able to encode to the format you<br>
choose.<br>
<div class="HOEnZb"><div class="h5"><br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br><br clear="all"><div><br></div>-- <br><div dir="ltr"><div>Robert W. Gorrell<br>Systems Architect, Identity and Access Management </div>
<div>University of NC at Greensboro<br><span style="white-space:nowrap">336-334-5954</span><br>PGP Key ID B36DB0CA<br></div></div>
</div>