<html><head><meta http-equiv="Content-Type" content="text/html charset=windows-1252"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;"><div><br></div><div>So the transientId is in the NameID in Subject of the SAML assertion in the example I previously sent.</div><div>Thanks Chris.</div><div><br></div><div>A different vendor is unable to properly interpret the SAML assertion from my IdP,</div><div>and I haven’t been able to fathom why not, but notice that despite parallel</div><div>debug log entries that transientId will be used to construct NameID, a corresponding</div><div>NameID is not in the Subject. Instead there’s an EncryptedID.</div><div><br></div><div>[We know I’m sending the required attributes to the right end point at the vendor SP, but</div><div>alas, the vendor’s support staff have no access to any logs on their side of the transaction,</div><div>and they have no example of a SAML assertion that works with their SP,</div><div>so I’m floundering on what might be wrong and I might need to change. The vendor </div><div>is Blackboard Transact and eAccounts.]</div><div><br></div><div><br></div><div><div style="font-size: 10px;"><br></div><div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194); position: static; z-index: auto;">10:13:00.500 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:585] </div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194); position: static; z-index: auto;">- Retaining attribute transientId which may be encoded as a name identifier of format urn:mace:shibboleth:1.0:nameIdentifier</div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194); position: static; z-index: auto;">10:13:00.500 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:585] </div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194); position: static; z-index: auto;">- Retaining attribute oktanameid which may be encoded as a name identifier of format urn:oasis:names:tc:SAML:2.0:nameid-format:transient</div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194); position: static; z-index: auto;">10:13:00.500 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:690] </div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194); position: static; z-index: auto;">- Selecting attribute to be encoded as a name identifier by encoder of type edu.internet2.middleware.shibboleth.common.attribute.encoding.SAML2NameIDEncoder</div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">10:13:00.500 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:717] </div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">- Selecting the first attribute that can be encoded in to a name identifier</div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194); position: static; z-index: auto;">10:13:00.500 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:501] </div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194); position: static; z-index: auto;">- Name identifier for relying party '<a href="https://sp.transactsp.com/shibboleth-sp/mgmt-ualaska-sp.blackboard.com/mgmt'">https://sp.transactsp.com/shibboleth-sp/mgmt-ualaska-sp.blackboard.com/mgmt'</a> will be built from attribute 'transientId'</div><div style="margin: 0px; background-color: rgb(255, 250, 194); position: static; z-index: auto;"><span style="font-size: 10px; font-family: Monaco;">10:13:00.501 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.AbstractSAML2ProfileHandler:868] </span></div><div style="margin: 0px; background-color: rgb(255, 250, 194); position: static; z-index: auto;"><span style="font-size: 10px; font-family: Monaco;">- </span><font face="Monaco">Using attribute 'transientId' supporting NameID format 'urn:oasis:names:tc:SAML:2.0:nameid-format:transient' to create the NameID for relying party '<a href="https://sp">https://sp</a><font size="1">...</font></font></div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194); position: static; z-index: auto;">10:13:00.501 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.AbstractSAML2ProfileHandler:733] </div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194); position: static; z-index: auto;">- Attempting to encrypt NameID to relying party '<a href="https://sp">https://sp</a>...'</div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194); position: static; z-index: auto;"><br></div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194); position: static; z-index: auto;">10:13:00.518 - DEBUG [edu.internet2.middleware.shibboleth.idp.profile.saml2.AbstractSAML2ProfileHandler:279] </div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">- Assertion to be encrypted is:</div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);"><br></div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);"><?xml version="1.0" encoding="UTF-8”?></div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);"><saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" ID="_8af127d6c08c145ea4d685a6d7b15935" IssueInstant="2014-09-24T18:13:00.497Z" Version="2.0"></div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);"> <saml2:Issuer Format="urn:oasis:names:tc:SAML:2.0:nameid-format:entity">urn:mace:incommon:alaska.edu</saml2:Issuer></div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);"><br></div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);"> <saml2:Subject></div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);"> <saml2:EncryptedID></div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);"> <xenc:EncryptedData xmlns:xenc="<a href="http://www.w3.org/2001/04/xmlenc#">http://www.w3.org/2001/04/xmlenc#</a>" Id="_534e2d085ea251250b2c002dd8145e0c" Type="<a href="http://www.w3.org/2001/04/xmlenc#Element">http://www.w3.org/2001/04/xmlenc#Element</a>"></div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);"> <xenc:EncryptionMethod Algorithm="<a href="http://www.w3.org/2001/04/xmlenc#aes128-cbc">http://www.w3.org/2001/04/xmlenc#aes128-cbc</a>" xmlns:xenc="<a href="http://www.w3.org/2001/04/xmlenc#">http://www.w3.org/2001/04/xmlenc#</a>"/></div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);"> <ds:KeyInfo xmlns:ds="<a href="http://www.w3.org/2000/09/xmldsig#">http://www.w3.org/2000/09/xmldsig#</a>"></div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);"> <xenc:EncryptedKey Id="_b20ce7ab579b8187fbb9317730046e00" xmlns:xenc="<a href="http://www.w3.org/2001/04/xmlenc#">http://www.w3.org/2001/04/xmlenc#</a>"></div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);"> <xenc:EncryptionMethod Algorithm="<a href="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p">http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p</a>" xmlns:xenc="<a href="http://www.w3.org/2001/04/xmlenc#">http://www.w3.org/2001/04/xmlenc#</a>"></div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);"> <ds:DigestMethod Algorithm="<a href="http://www.w3.org/2000/09/xmldsig#sha1">http://www.w3.org/2000/09/xmldsig#sha1</a>" xmlns:ds="<a href="http://www.w3.org/2000/09/xmldsig#">http://www.w3.org/2000/09/xmldsig#</a>"/></div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);"> </xenc:EncryptionMethod></div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);"> <ds:KeyInfo></div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);"> <ds:X509Data></div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194); position: static; z-index: auto;"> <ds:X509Certificate>...</ds:X509Certificate></div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);"> </ds:X509Data></div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);"> </ds:KeyInfo></div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);"> <xenc:CipherData xmlns:xenc="<a href="http://www.w3.org/2001/04/xmlenc#">http://www.w3.org/2001/04/xmlenc#</a>"></div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194); position: static; z-index: auto;"> <xenc:CipherValue>…………</xenc:CipherValue></div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);"> </xenc:CipherData></div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);"> </xenc:EncryptedKey></div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194); position: static; z-index: auto;"> </ds:KeyInfo></div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194); position: static; z-index: auto;"> <xenc:CipherData xmlns:xenc="<a href="http://www.w3.org/2001/04/xmlenc#">http://www.w3.org/2001/04/xmlenc#</a>"><xenc:CipherValue>…………</xenc:CipherValue></div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);"> </xenc:CipherData></div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);"> </xenc:EncryptedData></div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);"> </saml2:EncryptedID></div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);">…</div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);"> </saml2:Subject></div><div style="font-size: 10px; margin: 0px; font-family: Monaco; background-color: rgb(255, 250, 194);"><br></div></div><div style="font-size: 10px;"><br></div></div><div>the audit log affirms that transientId was sent:</div><div><br></div><div><span style="font-family: Monaco; font-size: 10px; background-color: rgb(255, 250, 194);">20140924T181300Z|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|_A5769940A111B3384C7CB42D7DD85A86|</span><a href="https://sp.transactsp.com/shibboleth-sp/mgmt-ualaska-sp.blackboard.com/mgmt|urn:mace:shibboleth:2.0:profiles:saml2:sso|urn:mace:incommon:alaska.edu|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|_102ff00baad293c853ccee7284f68bf6|djdewolfe|urn:oasis:names:tc:SAML:2.0:ac:classes:Password|BbTLastName,transientId,BbTFirstName,BbTemail,BbTusername,BbTbannerID,oktanameid,|_bb39377c01d1057a84575052456c6a20||" style="font-family: Monaco; font-size: 10px;">https://sp.transactsp.com/shibboleth-sp/mgmt-ualaska-sp.blackboard.com/mgmt|urn:mace:shibboleth:2.0:profiles:saml2:sso|urn:mace:incommon:alaska.edu|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|_102ff00baad293c853ccee7284f68bf6|djdewolfe|urn:oasis:names:tc:SAML:2.0:ac:classes:Password|BbTLastName,transientId,BbTFirstName,BbTemail,BbTusername,BbTbannerID,oktanameid,|_bb39377c01d1057a84575052456c6a20||</a></div><br><div><div>On Mon, 22 Sep 2014, at 14:04 , Christopher Bongaarts <<a href="mailto:cab@umn.edu">cab@umn.edu</a>> wrote:</div><br class="Apple-interchange-newline"><blockquote type="cite">
<meta content="text/html; charset=ISO-8859-1" http-equiv="Content-Type">
<div bgcolor="#FFFFFF" text="#000000">
Yes (the value is "_59dd...0492".)<br>
<br>
<div class="moz-cite-prefix">On 9/22/2014 5:02 PM, David Bantz
wrote:<br>
</div>
<blockquote cite="mid:409FE9F6-94C4-4992-87E3-E62B37051058@Alaska.edu" type="cite">
<meta http-equiv="Content-Type" content="text/html;
charset=ISO-8859-1">
Elementary question:
<div><span class="Apple-tab-span" style="white-space:pre"> </span>where,
in the IdP’s SAML assertion, is the transientId <<a moz-do-not-send="true" href="https://wiki.shibboleth.net/confluence/display/SHIB2/IdPTransientNameIdentifier">https://wiki.shibboleth.net/confluence/display/SHIB2/IdPTransientNameIdentifier</a>>
("released to anyone” as recommended)?</div>
<div>
<div><br>
</div>
<div><span class="Apple-tab-span" style="white-space:pre"> </span>Is
it the ID in the assertion... NameID in the Subject portion ?
</div>
<div><br>
</div>
<div>from process log:</div>
<div><br>
</div>
<div>
<div style="margin: 0px; font-family: Monaco;
background-color: rgb(255, 250, 194); position: static;
z-index: auto;"><span style="font-size: 10px;">11:40:34.099</span>
- DEBUG
[edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:585] </div>
<div style="margin: 0px; font-family: Monaco;
background-color: rgb(255, 250, 194); position: static;
z-index: auto;">- Retaining attribute transientId which may
be encoded as a name identifier of format
urn:mace:shibboleth:1.0:nameIdentifier</div>
<div style="margin: 0px; font-family: Monaco;
background-color: rgb(255, 250, 194); position: static;
z-index: auto; font-size: 11px;"><span style="font-size:
10px;">11:40:34.100</span> - DEBUG
[edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:585] </div>
<div style="margin: 0px; font-family: Monaco;
background-color: rgb(255, 250, 194); position: static;
z-index: auto; font-size: 11px;">- Retaining attribute
oktanameid which may be encoded as a name identifier of
format urn:oasis:names:tc:SAML:2.0:nameid-format:transient</div>
<div style="margin: 0px; font-family: Monaco;
background-color: rgb(255, 250, 194); font-size: 11px;
position: static; z-index: auto;"><span style="font-size:
10px;">11:40:34.100</span> - DEBUG
[edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:690] </div>
<div style="margin: 0px; font-family: Monaco;
background-color: rgb(255, 250, 194); font-size: 11px;
position: static; z-index: auto;">- Selecting attribute to
be encoded as a name identifier by encoder of type
edu.internet2.middleware.shibboleth.common.attribute.encoding.SAML2NameIDEncoder</div>
<div style="margin: 0px; font-family: Monaco;
background-color: rgb(255, 250, 194); font-size: 11px;"><span style="font-size: 10px;">11:40:34.100</span> - DEBUG
[edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:717] </div>
<div style="margin: 0px; font-family: Monaco;
background-color: rgb(255, 250, 194); font-size: 11px;">-
Selecting the first attribute that can be encoded in to a
name identifier</div>
<div style="margin: 0px; font-family: Monaco;
background-color: rgb(255, 250, 194); font-size: 11px;
position: static; z-index: auto;"><span style="font-size:
10px;">11:40:34.100</span> - DEBUG
[edu.internet2.middleware.shibboleth.idp.profile.AbstractSAMLProfileHandler:501] </div>
<div style="margin: 0px; font-family: Monaco;
background-color: rgb(255, 250, 194); font-size: 11px;
position: static; z-index: auto;">- Name identifier for
relying party '<a class="moz-txt-link-freetext" href="https://xn--nvgaaa/">https://••••</a>' will be built from attribute
'transientId'</div>
<div style="margin: 0px; font-family: Monaco;
background-color: rgb(255, 250, 194); font-size: 11px;
position: static; z-index: auto;"><span style="font-size:
10px;">11:40:34.101</span> - DEBUG
[edu.internet2.middleware.shibboleth.idp.profile.saml2.AbstractSAML2ProfileHandler:868] </div>
<div style="margin: 0px; font-family: Monaco;
background-color: rgb(255, 250, 194); font-size: 11px;
position: static; z-index: auto;">- Using attribute
'transientId' supporting NameID format
'urn:oasis:names:tc:SAML:2.0:nameid-format:transient' to
create the NameID for relying party '<a class="moz-txt-link-freetext" href="https://xn--nvgaaaaa/">https://••••••</a>'</div>
</div>
<div><br>
</div>
</div>
<div>SAML assertion fragments:</div>
<div style="font-size: 11px;"><br>
</div>
<div style="font-size: 11px;">
<div style="margin: 0px; font-family: Monaco; background-color:
rgb(255, 250, 194); position: static; z-index: auto;"><?xml
version="1.0" encoding="UTF-8"?><saml2p:Response
xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol"
Destination=<a class="moz-txt-link-rfc2396E" href="https://xn--nvgaaa/">"https://••••"</a>
ID="_5a83f3c5e2d3e9f6eb30a6fbcc98f1cc"
IssueInstant="2014-09-22T21:39:45.977Z" Version="2.0”>…</div>
</div>
<div style="margin: 0px; font-family: Monaco; background-color:
rgb(255, 250, 194); position: relative; z-index: 0; font-size:
11px;"><br>
</div>
<div style="margin: 0px; font-family: Monaco; background-color:
rgb(255, 250, 194); position: relative; z-index: 0;">
<div style="margin: 0px; font-size: 11px;"> <saml2:Assertion
xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"
ID="_ade790abe4f75d0b979b039ce18912ea"
IssueInstant="2014-09-22T21:39:45.977Z" Version="2.0"
xmlns:xs="<a moz-do-not-send="true" href="http://www.w3.org/2001/XMLSchema%3F">http://www.w3.org/2001/XMLSchema”</a>>...</div>
<div style="margin: 0px; font-size: 11px;"><br>
</div>
<div style="margin: 0px;">
<div style="margin: 0px; font-size: 11px;"><saml2:Subject></div>
<div style="margin: 0px; font-size: 11px;">
<saml2:NameID
Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient"
NameQualifier="urn:mace:incommon:alaska.edu"
SPNameQualifier="urn:amazon:webservices">_59ddcabea831dd654d8a75364ac70492</saml2:NameID>...</div>
</div>
</div>
<br>
<fieldset class="mimeAttachmentHeader"></fieldset>
<br>
</blockquote>
<br>
<pre class="moz-signature" cols="72">--
%% Christopher A. Bongaarts %% <a class="moz-txt-link-abbreviated" href="mailto:cab@umn.edu">cab@umn.edu</a> %%
%% OIT - Identity Management %% <a class="moz-txt-link-freetext" href="http://umn.edu/~cab">http://umn.edu/~cab</a> %%
%% University of Minnesota %% +1 (612) 625-1809 %%
</pre>
</div>
-- <br>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a></blockquote></div><br></body></html>