<div dir="ltr">Hi Scott. What should the format for the first encoder be then if this is used for email addresses?<div><br></div><div>I will clean up the attributes to just use one.</div><div><br></div><div>  -Andrew<br><div class="gmail_extra"><br><div class="gmail_quote">On Tue, Jan 20, 2015 at 1:37 PM, Cantor, Scott <span dir="ltr">&lt;<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">On 1/20/15, 6:22 PM, &quot;Andrew Cheung&quot; &lt;<a href="mailto:acheung@brookfieldres.com">acheung@brookfieldres.com</a>&gt; wrote:<br>
<br>
<br>
<br>
&gt;Hi, David. This is actually 1 domain in google (primary domain is :<br>
</span>&gt;<a href="http://dev.mySiteA.ca" target="_blank">dev.mySiteA.ca</a> &lt;<a href="http://dev.mysitea.ca/" target="_blank">http://dev.mysitea.ca/</a>&gt;)<br>
&gt; with a subdomain <a href="http://dev.mySiteB.com" target="_blank">dev.mySiteB.com</a> &lt;<a href="http://dev.mysiteb.com/" target="_blank">http://dev.mysiteb.com/</a>&gt;.<br>
<span class="">&gt;<br>
&gt;By the way I got it working. Here are the relevant pieces for those who<br>
&gt;are interested:<br>
<br>
</span>You don&#39;t need to block transients like that, you just need to specify the<br>
NameID format you want in the SP metadata for Google.<br>
<span class=""><br>
&gt;&lt;resolver:AttributeDefinition xsi:type=&quot;Simple&quot;<br>
&gt;xmlns=&quot;urn:mace:shibboleth:2.0:resolver:ad&quot; id=&quot;GoogleMySiteAEmail&quot;<br>
&gt;sourceAttributeID=&quot;mail&quot;&gt;<br>
&gt; &lt;resolver:Dependency ref=&quot;myLDAP&quot; /&gt;<br>
&gt;   &lt;resolver:AttributeEncoder xsi:type=&quot;enc:SAML1StringNameIdentifier&quot;<br>
&gt;nameFormat=&quot;urn:mace:shibboleth:1.0:nameIdentifier&quot;/&gt;<br>
&gt;  &lt;resolver:AttributeEncoder xsi:type=&quot;enc:SAML2StringNameID&quot;<br>
&gt;nameFormat=&quot;urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress&quot;/&gt;<br>
&gt;&lt;/resolver:AttributeDefinition&gt;<br>
<br>
</span>That first encoder is just plain wrong, that format is for transients in<br>
SAML 1.1.<br>
<br>
And I don&#39;t really follow why you&#39;d create two separate attributes for the<br>
domains if the value is the same.<br>
<span class="HOEnZb"><font color="#888888"><br>
-- Scott<br>
</font></span><div class="HOEnZb"><div class="h5"><br><br></div></div></blockquote></div>
</div></div></div>