<html><head></head><body><div>Understood, specifically the problem we get is on sign-in:</div><div><br></div><div>Unable to login using Idp User name is invalid, we are not able create
this
'AAdzZWNyZXQxM5JTIOlSYqZoH/iR0kKuxuDJU3xpBoZEjVIvDiPh9waP1uzFxFuDDSRuyQropDch4QqkOuNKlqHkVwRsFKvSYGOlviHTzqTAurhwZoFYrIwghICM6scHxePa'
in our system</div><div><br></div><div>From what I can tell from the SAML Tracer results, the part corresponds with what's in the NameID section:</div><div><br></div><div><pre id="txt"><saml2:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient"
NameQualifier="https://it-federation2.jmu.edu/idp/shibboleth"
SPNameQualifier="JMU.maps.arcgis.com"
>AAdzZWNyZXQxXb/rYm+ZcnLKv3HiQasbsmUCyznIMh4K2vAcCpEc6+BQm3kwBsjsKYJjVtnK6f6OGA5rWbejVo7Xh8SCKIKYhPLBUORj2gGOOUFC8pvywaocc5FDw71icBw+</saml2:NameID></pre></div><div><br></div><div><br></div><div>As I understand it, they need this to be in plaintext, and they believe this result to be indicative of encryption being enabled, even though I have encrypted assertions off and NameID encryption isn't default anymore in Shib 3.</div><div><br></div><div>I hope this makes sense.</div><div><br></div><div><div class="-x-evo-signature-wrapper"><span><pre><br class="Apple-interchange-newline">--
Brandon McKean
IT / Systems
Linux Administrator
(540)568-4235</pre><div><br></div></span></div></div><div><br></div><div>On Thu, 2015-06-25 at 15:09 +0200, Peter Schober wrote:</div><blockquote type="cite"><pre>* McKean, Brandon Scott - mckeanbs <<a href="mailto:mckeanbs@jmu.edu">mckeanbs@jmu.edu</a>> [2015-06-25 14:56]:
<blockquote type="cite">
The attribute resolver and attribute filter I can more or less directly
place into Shib 3, and turnining off assertion encryption I figured out
how to do from my previous question on here.
</blockquote>
It would help to know what it is that does /not/ work.
-peter
</pre></blockquote></body></html>