<html><head></head><body><div style="color:#000; background-color:#fff; font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;font-size:13px"><div id="yui_3_16_0_1_1455211193657_49778">Hi Scott,</div><div id="yui_3_16_0_1_1455211193657_49785"><br></div><div id="yui_3_16_0_1_1455211193657_49808" dir="ltr"> I'm still trying to get my head around this though my knowledge is growing. Still, I'm beating my head against a wall. Here's where I am.</div><div id="yui_3_16_0_1_1455211193657_49809" dir="ltr"><br></div><div id="yui_3_16_0_1_1455211193657_49832" dir="ltr">I've uncommented out the bean for email address saml-nameid.xml:</div><div id="yui_3_16_0_1_1455211193657_49854" dir="ltr"><br></div><div id="yui_3_16_0_1_1455211193657_49855" dir="ltr"> <!-- SAML 2 NameID Generation --><br> <util:list id="shibboleth.SAML2NameIDGenerators"><br><br> <ref bean="shibboleth.SAML2TransientGenerator" /><br><br> <!-- Uncommenting this bean requires configuration in saml-nameid.properties. --><br> <!--<br> <ref bean="shibboleth.SAML2PersistentGenerator" /><br> --><br><br> <bean parent="shibboleth.SAML2AttributeSourcedGenerator"<br> p:format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress"<br> p:attributeSourceIds="#{ {'mail'} }" /><br><br> </util:list><br></div><div id="yui_3_16_0_1_1455211193657_49922" dir="ltr"><br></div><div id="yui_3_16_0_1_1455211193657_49933" dir="ltr">I added the following to my attribute-filter.xml:</div><div id="yui_3_16_0_1_1455211193657_49959" dir="ltr"><br></div><div id="yui_3_16_0_1_1455211193657_49928" dir="ltr"><afp:AttributeFilterPolicy id="servicenow"><br> <afp:PolicyRequirementRule xsi:type="basic:AttributeRequesterString" value="https://umassmed.service-now.com" /><br><br> <afp:AttributeRule attributeID="NameID"><br> <afp:PermitValueRule xsi:type="basic:ANY" /><br> </afp:AttributeRule><br><br><afp:AttributeRule attributeID="transientId"><br> <afp:DenyValueRule xsi:type="basic:ANY" /><br> </afp:AttributeRule><br><br></afp:AttributeFilterPolicy><br></div><div id="yui_3_16_0_1_1455211193657_49961" dir="ltr"><br></div><div id="yui_3_16_0_1_1455211193657_49960" dir="ltr"> I suspect that the transientid is unecessary but a colleague suggested it based on what we got from our SP in the metadata which is below:</div><div id="yui_3_16_0_1_1455211193657_50022" dir="ltr"><br></div><div id="yui_3_16_0_1_1455211193657_50023" dir="ltr"><NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat></div><div id="yui_3_16_0_1_1455211193657_50054" dir="ltr"><br></div><div id="yui_3_16_0_1_1455211193657_50055" dir="ltr"> Reading through <a id="yui_3_16_0_1_1455211193657_50171" href="https://wiki.shibboleth.net/confluence/display/IDP30/CustomNameIDGenerationConfiguration">CustomNameIDGenerationConfiguration - Identity Provider 3 - Confluence</a></div><div dir="ltr"><br></div><div dir="ltr"> I think I have everything in place but I'm still getting a transient string rather than the email address. What am I missing?</div><div id="yui_3_16_0_1_1455211193657_50262" dir="ltr"><br></div><div style="width:450px; font-family: 'Georgia', 'Times', 'Times New Roman', 'serif';margin-top:5px; margin-bottom: 5px; background-color: #ffffff;" id="enhancrCard_0" class="link-enhancr-attachment link-enhancr-element richcompose-card" contenteditable="false"><table class="link-enhancr-element" style="width:450px; height:auto; position: relative; display: block;" border="0" cellpadding="0" cellspacing="0"><tbody><tr class="link-enhancr-element"><td class="link-enhancr-element" colspan="7" style="height: 1px; background-color: #e5e5e5; font-size: 1px; border-collapse: collapse;"><div class="link-enhancr-element" style="height: 1px; background-color: #e5e5e5; font-size: 1px; line-height:0px;"> </div></td></tr><tr class="link-enhancr-element"><td rowspan="5" class="link-enhancr-element" style="width: 1px; background-color: #e5e5e5; font-size: 1pt; border-collapse: collapse;"><div class="link-enhancr-element" style="width: 1px; background-color: #e5e5e5; font-size: 1pt;"> </div></td><td rowspan="5" class="link-enhancr-element" style="width: 14px; background-color: #ffffff; font-size: 0pt; border-collapse: collapse;"><div class="link-enhancr-element" style="width: 14px; background-color: #ffffff; font-size: 14pt;"> </div></td><td colspan="2" class="link-enhancr-element" style="height: 6px; background-color: #ffffff; font-size: 0pt; border-collapse: collapse;"><div class="link-enhancr-element" style="height: 6px; background-color: #ffffff; font-size: 6pt;"> </div></td><td rowspan="5" class="link-enhancr-element" style="width: 20px; background-color: #ffffff; font-size: 0pt; border-collapse: collapse;"><div class="link-enhancr-element" style="width: 20px; background-color: #ffffff; font-size: 20pt;"> </div></td><td class="link-enhancr-element" rowspan="5" style="width: 1px; background-color: #e5e5e5; font-size: 1pt; border-collapse: collapse;" width="1"><div class="link-enhancr-element" style="width: 1px; background-color: #e5e5e5; font-size: 1pt;"> </div></td></tr><tr><td class="link-enhancr-element" colspan="2" style="width: 100%; vertical-align: middle; font-family: 'Georgia', 'Times', 'Times New Roman', 'serif';"><div class="link-enhancr-text-part link-enhancr-element" style="line-height:16.5px; background-color: #ffffff; width: 414px;"><div class="link-enhancr-element" style="word-wrap: break-word; word-break: break-all;"><span class="link-enhancr-element icon icon-shrink link-enhancr-toggle"></span><span class="link-enhancr-element icon icon-close link-enhancr-delete"></span><a href="https://wiki.shibboleth.net/confluence/display/IDP30/CustomNameIDGenerationConfiguration" class="link-enhancr-card-urlWrapper link-enhancr-element" style="text-decoration: none !important;text-decoration:none; color: #000000 !important; line-height: 100%; font-size: 18px; display: block;"><span class="link-enhancr-element link-enhancr-card-title" style="margin: 0; font-weight: normal;margin-bottom: 3px; font-size: 18px; line-height: 21px; max-height: 43px; color: #000000; overflow: hidden !important; display: inline-block;">CustomNameIDGenerationConfiguration - Identity Provider 3 - Confluence</span></a><div style="font-size: 13px; line-height: 20px; color: #999999; max-height: 81px; font-family: 'Georgia', 'Times', 'Times New Roman', 'serif';overflow: hidden;" class="link-enhancr-card-description link-enhancr-element">Overview An identifier that is neither "transient" nor "persistent" is of a more general category referred to for convenience as a "custom" identifier. </div></div></div></td></tr><tr><td colspan="2" class="link-enhancr-element" style="height: 6px; background-color: #ffffff; font-size: 0pt; border-collapse: collapse;"><div class="link-enhancr-element" style="height: 6px; background-color: #ffffff; font-size: 6pt;"></div></td></tr><tr><td class="link-enhancr-element" style="vertical-align: middle; font-family: 'Arial', 'Helvetica Neue', 'Helvetica', 'sans-serif';"><div class="link-enhancr-element" style="font-size: 0pt;"><a href="https://wiki.shibboleth.net/confluence/display/IDP30/CustomNameIDGenerationConfiguration" class="link-enhancr-card-url link-enhancr-element" style="color: black; text-decoration: none !important;text-decoration:none;cursor:pointer !important;" target="_blank"><span id="yui_3_16_0_1_1455211193657_50214" class="link-enhancr-element link-enhancr-view-on" style="display: inline-block; line-height: 11px; max-width: 314px; min-width: 254px; overflow: hidden; max-height: 13px; word-break: break-all;"><span class="link-enhancr-element link-enhancr-mobile-no-resize" style="vertical-align:middle; font-size: 9px; line-height: 11px; color: #999999; -moz-text-size-adjust: none; -ms-text-size-adjust: none; -webkit-text-size-adjust:none; text-size-adjust:none;">View on <span style="font-weight: bold" class="link-enhancr-view-on-domain">wiki.shibboleth.net</span></span></span></a></div></td><td class="link-enhancr-element" style="vertical-align: middle; width: 100px; font-family: 'Arial', 'Helvetica Neue', 'Helvetica', 'sans-serif';"><div class="link-enhancr-element link-enhancr-preview-wrapper" style="max-width: 100px; min-width: 80px; overflow: hidden; text-align: right; line-height: 11px; max-height: 13px; font-size: 0pt;"><span class="link-enhancr-element link-enhancr-preview-by link-enhancr-mobile-no-resize" style="vertical-align:middle; font-size: 9px; line-height: 11px; color: #999999; -moz-text-size-adjust: none; -ms-text-size-adjust: none; -webkit-text-size-adjust:none; text-size-adjust:none;">Preview by Yahoo</span></div></td></tr><tr><td colspan="2" class="link-enhancr-element" style="height: 9px; background-color: #ffffff; font-size: 0pt; border-collapse: collapse;"><div class="link-enhancr-element" style="height: 9px; background-color: #ffffff; font-size: 9pt;"></div></td></tr><tr class="link-enhancr-element"><td class="link-enhancr-element" colspan="7" style="height: 1px; background-color: #e5e5e5; font-size: 1px; border-collapse: collapse;"><div class="link-enhancr-element" style="height: 1px; background-color: #e5e5e5; font-size: 1px; line-height:0px"> </div></td></tr></tbody></table></div><div><br></div><div id="yui_3_16_0_1_1455211193657_50263">Thanks</div><div id="yui_3_16_0_1_1455211193657_50264">-Bob<br></div><div id="yui_3_16_0_1_1455211193657_49811">--<br></div><div id="yui_3_16_0_1_1455211193657_49770">Bob Lamothe<br>robert_lamothe@yahoo.com<br>KB1BOB<br>603-918-6336<br><br></div> <div class="qtdSeparateBR"><br><br></div><div style="display: block;" class="yahoo_quoted"> <div style="font-family: HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif; font-size: 13px;"> <div style="font-family: HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif; font-size: 16px;"> <div dir="ltr"><font face="Arial" size="2"> On Tuesday, February 2, 2016 5:38 PM, "Cantor, Scott" <cantor.2@osu.edu> wrote:<br></font></div> <br><br> <div class="y_msg_container">> I have not doubt that I'm misunderstanding, documentation seems very<br clear="none">> incomplete so I'm struggling through this at every step.<br clear="none"><br clear="none">The documentation simply assumes you know a lot about SAML and has never been written to be approachable without that baseline, that's why most people struggle.<br clear="none"><br clear="none">> Ok, so how do I do this? The vendor is using NameID and wants it to be<br clear="none">> unique, they're recommending it be the email address.<br clear="none"><br clear="none">Using email addresses is often a bad idea, and that's not a Shibboleth thing, it's just bad IDM and application practice. It's not really in scope of this list to talk about all the reasons why and the trade offs, but those are things that come from years of experience integrating systems.<br clear="none"><br clear="none">Most business integrations tend to rely on internal keys like employee IDs and the like, since they don't have to be globally unique, just unique in a silo.<br clear="none"><br clear="none">Email address, despite it being a bad choice, is the de facto standard identifier that happens to be globally unique, that's why people outside higher ed gravitate to it.<br clear="none"><br clear="none">Shibboleth prefers the use of SAML Attributes to the NameID element. Vendors are sloppy and don't know what they want most of the time, but requiring NameID isn't unusual, and is the major source of friction using Shibboleth with those use cases.<br clear="none"> <br clear="none">> This suggests that I can override NameID per SP, if so, how do I do this?<br clear="none"><br clear="none"><a shape="rect" href="https://wiki.shibboleth.net/confluence/display/IDP30/CustomNameIDGenerationConfiguration" target="_blank">https://wiki.shibboleth.net/confluence/display/IDP30/CustomNameIDGenerationConfiguration</a><br clear="none"><br clear="none">The documentation refers to them as a "custom" NameID. They can be per-SP but they should not be. NameIDs have Formats and a given Format should never be used to carry different data. SPs can request the Format they want, or you have to manipulate the metadata or configuration to ensure the Format desired gets used. You do not want to start creating rules that generate a Format differently by SP, though it's possible.<div class="yqt6768297559" id="yqtfd73226"><br clear="none"><br clear="none">-- Scott<br clear="none"> <br clear="none">-- <br clear="none">To unsubscribe from this list send an email to <a shape="rect" ymailto="mailto:users-unsubscribe@shibboleth.net" href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br clear="none"></div><br><br></div> </div> </div> </div></div></body></html>