<div dir="ltr"><div><br></div><div class="gmail_extra"><br><div class="gmail_quote">On Wed, Sep 30, 2015 at 4:07 PM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex"><span class="">On 9/30/15, 3:53 PM, "users on behalf of Michael Dahlberg" <<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:olgamirth@gmail.com">olgamirth@gmail.com</a>> wrote:<br>
<br>
>My reading of this is that when I release the attribute "cnIdentifiedName" that the "commonName" attribute retrieved from our LDAP server will be SAML2 encoded and released in the Subject NameID field.<br>
<br>
</span>If that Format is selected. If the SP doesn't tell it anything, the metadata doesn't tell it anything, and you don't tell it anything, then what gets selected is the same as always.<br></blockquote><div><br></div><div><br></div><div><br></div><div>Yes, my apologies.  Of course, I am releasing that attribute in the attribute-filter.xml file:<div><br></div><div><div><afp:AttributeFilterPolicy></div><div>        <afp:PolicyRequirementRule xsi:type="basic:AttributeRequesterString" value="benefitfocus.com:sp" /></div><div><br></div><div>        <afp:AttributeRule attributeID="cnIdentifiedName"></div><div>            <afp:PermitValueRule xsi:type="basic:ANY" /></div><div>        </afp:AttributeRule></div><div><br></div><div>    </afp:AttributeFilterPolicy></div></div><div><br></div><div>I should have specifically delineated that.  I release the WindowsDomainQualifiedName in a similar fashion and the correct value gets released.</div></div><div><br></div><div> </div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex">
<br>
The selection process is documented [1]. I don't know why it's so confusing, you can probably help with that.<br>
<br><br></blockquote><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex">
<br>
[1] <a href="https://wiki.shibboleth.net/confluence/display/SHIB2/IdPNameIdentifier" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/display/SHIB2/IdPNameIdentifier</a> (bottom of page)<br>
<div class=""><div class="h5"><br></div></div></blockquote><div><br></div><div><br></div><div>I appreciate your help with this.  Unfortunately, most of the Shibboleth wiki pages are long on description and short on examples. I appreciate the description of a persistent identifier but I don't know how it is used, what it releases, or where it releases it in the SAML payload.  I usually stop reading that particular page at that point.  I agree, I should continue on. </div><div> </div><div><div><br></div><div><br></div><div>> It's probably also worth noting that there is not an e-mailAddress nameFormat unique to SAML 2.0, so your third line below should still reference the 1.1 emailAddress name format type:</div><div><br></div><div>>       <resolver:AttributeEncoder xsi:type="enc:SAML2StringNameID" nameFormat="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress" /></div></div><div><br></div><div><br></div><div>I'm not sure how I would know that there "is not an e-mailAddress nameFormat unique to SAML 2.0" and what effect changing that nameFormat has on what is released, how it is released and where it is released..</div><div><br></div><div>Given that I am releasing the cnIdentifiedName in the attribute-filter, that other attributes can be released without blocking the transientID, would there be any other reason why the transientID is released and not the cnIdentifiedName?</div><div><br></div><div>Thanks again,</div><div>Mike</div><div><br></div></div><br></div></div>