<div style="color:#000; background-color:#fff; font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;font-size:10px"><div id="yui_3_16_0_1_1431390676838_56206" class="" style="">Thanks for the quick answer.</div><div id="yui_3_16_0_1_1431390676838_56206" class="" style=""><br class="" style=""></div><div id="yui_3_16_0_1_1431390676838_56206" class="" style="" dir="ltr">1 .I did not provide the salt from my configuration file so no compromise here :) I shoudl have used 123456 to make it more clear</div><div id="yui_3_16_0_1_1431390676838_56206" class="" style="">2. The username is indeed a numerical value</div><div id="yui_3_16_0_1_1431390676838_56206" class="" style="">3. I did uncomment the shibboleth.SAML2PersistentGenerator bean in saml-nameid.xml</div><div id="yui_3_16_0_1_1431390676838_56206" class="" style="" dir="ltr">4. in my attribute-filter.xml file I've included the following</div><div id="yui_3_16_0_1_1431390676838_56206" class="" dir="ltr" style=""><afp:AttributeFilterPolicy></div><div id="yui_3_16_0_1_1431390676838_56206" class="" dir="ltr" style=""> <afp:PolicyRequirementRule xsi:type="basic:AttributeRequesterString" value="<provider SP>" /></div><div id="yui_3_16_0_1_1431390676838_56206" class="" dir="ltr" style=""><br class="" style=""></div><div id="yui_3_16_0_1_1431390676838_56206" class="" dir="ltr" style=""> <afp:AttributeRule attributeID="persistentNameIdSourceUid"></div><div id="yui_3_16_0_1_1431390676838_56206" class="" dir="ltr" style=""> <afp:PermitValueRule xsi:type="basic:ANY" /></div><div id="yui_3_16_0_1_1431390676838_56206" class="" dir="ltr" style=""> </afp:AttributeRule></div><div id="yui_3_16_0_1_1431390676838_56206" class="" dir="ltr" style=""> </div><div id="yui_3_16_0_1_1431390676838_56206" class="" dir="ltr" style=""> </afp:AttributeFilterPolicy></div><div id="yui_3_16_0_1_1431390676838_56206" class="" dir="ltr" style=""><br></div><div id="yui_3_16_0_1_1431390676838_56206" class="" dir="ltr" style="">In the consent screen I do this this attribute listed as being released:</div><div id="yui_3_16_0_1_1431390676838_56206" class="" dir="ltr" style="">------------------------------</div><div id="yui_3_16_0_1_1431390676838_56206" class="" dir="ltr" style="">You are about to access the service:</div><div id="yui_3_16_0_1_1431390676838_56206" class="" dir="ltr" style="">xxxxx.com</div><div id="yui_3_16_0_1_1431390676838_56206" class="" dir="ltr" style="">Information to be Provided to Service</div><div id="yui_3_16_0_1_1431390676838_56206" class="" dir="ltr" style="">persistentNameIdSourceUid<span class="" style="white-space:pre"> </span> 123456789</div><div id="yui_3_16_0_1_1431390676838_56206" class="" dir="ltr" style="">---------------------------------</div><div id="yui_3_16_0_1_1431390676838_56206" class="" dir="ltr" style=""><br></div><div id="yui_3_16_0_1_1431390676838_56206" class="" dir="ltr" style="">Thanks for your insights!</div><div id="yui_3_16_0_1_1431390676838_56206" class="" dir="ltr" style=""><br></div><div id="yui_3_16_0_1_1431390676838_56206" class="" dir="ltr" style="">Katia</div><header class="" style="" id="yui_3_16_0_1_1431390676838_56593"> </header><div style="margin-top: 70px;" class="" id="yui_3_16_0_1_1431390676838_56594"></div><div style="font-family: HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif; font-size: 10px;" id="yui_3_16_0_1_1431390676838_56209"><div style="font-family: HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif; font-size: 16px;" id="yui_3_16_0_1_1431390676838_56208"><div dir="ltr" id="yui_3_16_0_1_1431390676838_56207"> <font size="2" face="Arial" id="yui_3_16_0_1_1431390676838_56210"> <b><span style="font-weight:bold;">From:</span></b> "Cantor, Scott E. [via Shibboleth]" <<a href="/user/SendEmail.jtp?type=node&node=7614934&i=0" target="_top" rel="nofollow" link="external">[hidden email]</a>><br> <b><span style="font-weight: bold;">To:</span></b> Katia <<a href="/user/SendEmail.jtp?type=node&node=7614934&i=1" target="_top" rel="nofollow" link="external">[hidden email]</a>> <br> <b><span style="font-weight: bold;">Sent:</span></b> Monday, May 11, 2015 9:29 PM<br> <b><span style="font-weight: bold;">Subject:</span></b> Re: Attribute Resolver Migrating to IDP30 and generatin persistent NameId using PrincipalName<br> </font> </div> <div class="y_msg_container" id="yui_3_16_0_1_1431390676838_56211"><br><div id="yiv5188151919">
On 5/12/15, 1:07 AM, "Katia" <<a rel="nofollow" id="yui_3_16_0_1_1431390676838_56293" href="" target="_top" link="external">[hidden email]</a>> wrote:
<br><br><br><div class="yiv5188151919shrinkable-quote" id="yui_3_16_0_1_1431390676838_56212"><div class='shrinkable-quote'><br>>I've went through the post from 2 weeks ago from Sara (IdPv3 and
<br>>generating
<br>>persistent NameID) and the subsequent responses and I followed the steps
<br>>detailed in the documentation to support PersistentId NameId
<br>>
<br>>Content of
<br>>saml-nameid.properties
<br>>
<br>>idp.persistentId.generator = shibboleth.ComputedPersistentIdGenerator
<br>>idp.persistentId.sourceAttribute = persistentNameIdSourceUid
<br>>idp.persistentId.salt = XXXXXXX
</div></div>If that's the real salt, you've just compromised the opacity of all those
<br>IDs. That's like divulging a private key.
<br><div class="yiv5188151919shrinkable-quote" id="yui_3_16_0_1_1431390676838_56222"><div class='shrinkable-quote'><br>>However my attribute_resolver configuration that worked in V2 is now
<br>>failing
<br>>
<br>> <resolver:AttributeDefinition id="persistentNameIdSourceUid"
<br>>xsi:type="ad:PrincipalName">
<br>> <resolver:AttributeEncoder
<br>>xsi:type="enc:SAML1StringNameIdentifier"
<br>>nameFormat="urn:mace:shibboleth:1.0:nameIdentifier" />
<br>> <resolver:AttributeEncoder xsi:type="enc:SAML2StringNameID"
<br>>nameFormat="urn:oasis:names:tc:SAML:2.0:nameid-format:persistent" />
<br>> </resolver:AttributeDefinition>
</div></div>That's putting the user's principal name into a SAML NameID with a format
<br>specifically designed for use with opaque pairwise IDs in the SAMl 2 case,
<br>and the transient format in the case of SAML 1. That's not correct. It
<br>"works", but it's wrong. Those encoders should not be there, or at the
<br>least they should have different formats.
<br><br>Also, it's a bad idea to generate persistent IDs using a username as a
<br>seed, unless that username is opaque/numeric/whatever. Otherwise it's not
<br>stable.
<br><br>>In IDP30 I get this error using the same provider
<br>>
<br>>WARN [org.opensaml.saml.saml2.profile.impl.AddNameIDToSubjects:337] -
<br>>Profile Action AddNameIDToSubjects: Request specified use of an
<br>>unsupportable identifier format:
<br>>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent
<br>>
<br>>Let me know if you need more details.
<br><br>I guess, yes. My best guess is maybe the persistentNameIdSourceUid
<br>attribute is not being released.
<br><br>You also might not have uncommented the
<br>shibboleth.SAML2PersistentGenerator bean in
<br>saml-nameid.xml, which the documentation includes as a step. Though given
<br>the rest of that, I think if the attribute were released it would be
<br>working because of the legacy use of the resolver and the
<br>SAML2StringNameID encoder, and you'd get a persistent NameID with the
<br>username in it.
<br><br>-- Scott
<br><br>--
<br>To unsubscribe from this list send an email to <a rel="nofollow" href="" target="_top" link="external">[hidden email]</a>
<br>
<br>
<br>
<hr noshade="" size="1" color="#cccccc">
<div style="color:#444;font:12px tahoma, geneva, helvetica, arial, sans-serif;">
<div style="font-weight:bold;">If you reply to this email, your message will be added to the discussion below:</div>
<a rel="nofollow" target="_blank" href="http://shibboleth.1660669.n2.nabble.com/Attribute-Resolver-Migrating-to-IDP30-and-generatin-persistent-NameId-using-PrincipalName-tp7614884p7614885.html" link="external">http://shibboleth.1660669.n2.nabble.com/Attribute-Resolver-Migrating-to-IDP30-and-generatin-persistent-NameId-using-PrincipalName-tp7614884p7614885.html</a>
</div>
<div style="color:#666;font:11px tahoma, geneva, helvetica, arial, sans-serif;margin-top:.4em;line-height:1.5em;">
To unsubscribe from Attribute Resolver Migrating to IDP30 and generatin persistent NameId using PrincipalName, <a rel="nofollow" target="_blank" href="" link="external">click here</a>.<br>
<a rel="nofollow" target="_blank" href="http://shibboleth.1660669.n2.nabble.com/template/NamlServlet.jtp?macro=macro_viewer&id=instant_html%21nabble%3Aemail.naml&base=nabble.naml.namespaces.BasicNamespace-nabble.view.web.template.NabbleNamespace-nabble.view.web.template.NodeNamespace&breadcrumbs=notify_subscribers%21nabble%3Aemail.naml-instant_emails%21nabble%3Aemail.naml-send_instant_email%21nabble%3Aemail.naml" style="font:9px serif;" link="external">NAML</a>
</div></div><br><br></div> </div> </div> </div>
<br/><hr align="left" width="300" />
View this message in context: <a href="http://shibboleth.1660669.n2.nabble.com/Attribute-Resolver-Migrating-to-IDP30-and-generatin-persistent-NameId-using-PrincipalName-tp7614884p7614934.html">Re: Attribute Resolver Migrating to IDP30 and generatin persistent NameId using PrincipalName</a><br/>
Sent from the <a href="http://shibboleth.1660669.n2.nabble.com/Shibboleth-Users-f1660767.html">Shibboleth - Users mailing list archive</a> at Nabble.com.<br/>