<html><head></head><body><div style="color:#000; background-color:#fff; font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;font-size:13px"><div id="yiv9311727665"><div id="yui_3_16_0_1_1455285036196_4033"><div id="yui_3_16_0_1_1455285036196_4032" style="color:#000;background-color:#fff;font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;font-size:13px;"><div id="yui_3_16_0_1_1455285036196_4066">Here are the logs from shibtest.org, I'm using that for debugging as the log files are easier to read than from the SP.<br></div><div id="yiv9311727665yui_3_16_0_1_1455285036196_2966"><br clear="none"></div><pre id="yiv9311727665yui_3_16_0_1_1455285036196_2969">2016-02-12 08:55:27 DEBUG Shibboleth.SSO.SAML2 [5]: decrypted Assertion: <saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" ID="_4dd7fe1bbf06b74768126d64839634a3" IssueInstant="2016-02-12T13:55:26.742Z" Version="2.0"><saml2:Issuer>https://shibboleth.umassmed.edu/idp/shibboleth</saml2:Issuer><saml2:Subject><saml2:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient" NameQualifier="https://shibboleth.umassmed.edu/idp/shibboleth" SPNameQualifier="https://sp.testshib.org/shibboleth-sp">AAhzZWNyZXQzMpcOxEiCUYgvWjbRtBc9wjXVN27uQFSNDhJR9/Ou+kVuEcTKWZtZlQcQpB26GcK3BuP4tqV+G97nr8BB1GODPNx1DVeGUSjtlz7zUWvr5lHanlhhIqp3z1USlRO0bJgsGE1A7sDcluzHLks=</saml2:NameID><saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"><saml2:SubjectConfirmationData Address="172.17.44.170" InResponseTo="_049b45a5edfe7180db724996b18f1b0a" NotOnOrAfter="2016-02-12T14:00:26.753Z" Recipient="https://sp.testshib.org/Shibboleth.sso/SAML2/POST"/></saml2:SubjectConfirmation></saml2:Subject><saml2:Conditions NotBefore="2016-02-12T13:55:26.742Z" NotOnOrAfter="2016-02-12T14:00:26.742Z"><saml2:AudienceRestriction><saml2:Audience>https://sp.testshib.org/shibboleth-sp</saml2:Audience></saml2:AudienceRestriction></saml2:Conditions><saml2:AuthnStatement AuthnInstant="2016-02-12T13:55:26.509Z" SessionIndex="_54b0be6b4dfafd0e8bb03a67753c71a4"><saml2:SubjectLocality Address="172.17.44.170"/><saml2:AuthnContext><saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml2:AuthnContextClassRef></saml2:AuthnContext></saml2:AuthnStatement><saml2:AttributeStatement><saml2:Attribute FriendlyName="uid" Name="urn:oid:0.9.2342.19200300.100.1.1" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>LamotheR</saml2:AttributeValue></saml2:Attribute><saml2:Attribute FriendlyName="mail" Name="urn:oid:0.9.2342.19200300.100.1.3" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>Robert.Lamothe@umassmed.edu</saml2:AttributeValue></saml2:Attribute><saml2:Attribute FriendlyName="eduPersonAffiliation" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.1" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>staff</saml2:AttributeValue></saml2:Attribute><saml2:Attribute FriendlyName="eduPersonTargetedID" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.10" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue><saml2:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:persistent" NameQualifier="https://shibboleth.umassmed.edu/idp/shibboleth" SPNameQualifier="https://sp.testshib.org/shibboleth-sp">XgQzYSIOcCKtS8gcaeSXYCyfsfE=</saml2:NameID></saml2:AttributeValue></saml2:Attribute><saml2:Attribute FriendlyName="displayName" Name="urn:oid:2.16.840.1.113730.3.1.241" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>Lamothe, Robert</saml2:AttributeValue></saml2:Attribute><saml2:Attribute FriendlyName="sn" Name="urn:oid:2.5.4.4" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>Lamothe</saml2:AttributeValue></saml2:Attribute><saml2:Attribute FriendlyName="givenName" Name="urn:oid:2.5.4.42" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>Robert</saml2:AttributeValue></saml2:Attribute><saml2:Attribute FriendlyName="eduPersonPrincipalName" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>lamother@umassmed.edu</saml2:AttributeValue></saml2:Attribute><saml2:Attribute FriendlyName="title" Name="urn:oid:2.5.4.12" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><saml2:AttributeValue>Sr System Admin.</saml2:AttributeValue></saml2:Attribute></saml2:AttributeStatement></saml2:Assertion><br clear="none"><br clear="none"><br clear="none"></pre><div id="yiv9311727665yui_3_16_0_1_1455285036196_2973"><span></span></div><div id="yiv9311727665yui_3_16_0_1_1455285036196_2972"><div id="yui_3_16_0_1_1455285036196_4652" dir="ltr">    According to  CustomNameIDGenerationConfiguration, I followed the steps in General Procedure and uncommented out the code for the SAML 2.0 Email Format Examples, I included that in my last message.</div><div id="yui_3_16_0_1_1455285036196_4654" dir="ltr"><br></div><div id="yui_3_16_0_1_1455285036196_4655" dir="ltr">   I'm a little confused though, the example has a type of <code id="yui_3_16_0_1_1455285036196_4658" class="xml string">rn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress <font id="yui_3_16_0_1_1455285036196_4832" face="HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif">The metadata is asking for </font>urn:oasis:names:tc:SAML:2.0:nameid-format:transient <font id="yui_3_16_0_1_1455285036196_4952" face="HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif">Do they need to match?  The metadata was generated by the SP so I'm thinking the format has to remain as they sent it, is that true?  Can I change  </font><font id="yui_3_16_0_1_1455285036196_4980" face="HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif"><NameIDFormat> to match </font><font id="yui_3_16_0_1_1455285036196_5070" face="HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif">what's in saml-nameid.xml?  Or do I change saml-nameid.xml to match the <NameIDFormat> that our SP is looking for?</font></code></div><div id="yui_3_16_0_1_1455285036196_5071" dir="ltr"><br><code id="yui_3_16_0_1_1455285036196_4658" class="xml string"></code></div><div id="yui_3_16_0_1_1455285036196_5073" dir="ltr"><code id="yui_3_16_0_1_1455285036196_4658" class="xml string"><font id="yui_3_16_0_1_1455285036196_5072" face="HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif">    Please correct me if I'm wrong, but I need to make changes in saml-nameid.xml, and possibly saml-nameid.properties right?  I'm digesting every document I can find, but few provide practical examples, they're all running at a high level.  </font></code><br></div><div id="yui_3_16_0_1_1455285036196_5163" dir="ltr"><br></div><div id="yui_3_16_0_1_1455285036196_5165" dir="ltr">    If I understand the example in CustomNameIDGenerationConfiguration, my failure is most likely in step 4 or 5, either my format is wrong or it's my trigger.</div><div id="yui_3_16_0_1_1455285036196_5287" dir="ltr"><br></div><div dir="ltr">Regards</div><div dir="ltr">-Bob<br></div><div id="yui_3_16_0_1_1455285036196_5164" dir="ltr">--<br clear="none"></div></div><div class="yiv9311727665signature" id="yiv9311727665yui_3_16_0_1_1455285036196_2971"><div id="yiv9311727665yui_3_16_0_1_1455285036196_2970">Bob Lamothe<br clear="none">robert_lamothe@yahoo.com<br clear="none">KB1BOB<br clear="none">603-918-6336<br clear="none"><br clear="none"></div></div> <div id="yui_3_16_0_1_1455285036196_4677" class="yiv9311727665qtdSeparateBR"><br clear="none"><br clear="none"></div><div class="yiv9311727665yqt4920763759" id="yiv9311727665yqt11682"></div></div></div></div><div class=".yiv9311727665yahoo_quoted"> <div style="font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;font-size:13px;"> <div style="font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;font-size:16px;"> <div dir="ltr"><font face="Arial" size="2"> On Thursday, February 11, 2016 7:39 PM, "Cantor, Scott" <cantor.2@osu.edu> wrote:<br clear="none"></font></div>  <br clear="none"><br clear="none"> <div class="yiv9311727665y_msg_container">> I added the following to my attribute-filter.xml:<br clear="none"><br clear="none">The default behavior of the attribute-sourced NameID generator is to rely on released attributes, so the attribute you need to "release" to the SP is the mail attribute. So what you're doing here isn't going to help. Whether that's your problem is a different issue, but it won't work until you fix that. Releasing "NameID" is meaningless. There is no such attribute.<br clear="none"><br clear="none">You can also, if you prefer, configure the generator plugin to allow sourcing of "unfiltered" attributes so that you don't have to explicitly release the source attribute by setting the useUnfilteredAttributes property of the generator.<br clear="none"><br clear="none">>     I suspect that the transientid is unecessary but a colleague suggested it<br clear="none">> based on what we got from our SP in the metadata which is below:<br clear="none"><br clear="none">There is nothing in the filter policy that has any effect on transient identifiers, period.<br clear="none"><br clear="none">>     I think I have everything in place but I'm still getting a transient string rather<br clear="none">> than the email address.  What am I missing?<br clear="none"><br clear="none">Well, with no logs, I'm just guessing. You didn't release mail, so that isn't going to work, but even if you did, I don't think there's anything here that would suggest it will pick anything but transient, because the metadata is explicit about wanting that.<br clear="none"><br clear="none">I've documented the NameID Format selection algorithm in as much detail as I know how to:<br clear="none"><br clear="none"><a rel="nofollow" shape="rect" target="_blank" href="https://wiki.shibboleth.net/confluence/display/IDP30/NameIDGenerationConfiguration">https://wiki.shibboleth.net/confluence/display/IDP30/NameIDGenerationConfiguration</a><br clear="none"><br clear="none">I think it should be quite clear from that that if the metadata requests transient, that's what you're getting.<br clear="none"><br clear="none">We can have a discussion about whether that's the right thing to do, but that's what we do. If the metadata lists only transient, I don't believe there's *anything* you could do that would give you a different outcome. The most it would do is include nothing, if you blocked the support for transients. It would never include a Format that the SP doesn't support. If the metadata contains *nothing*, then the rest of the machinery takes over because that means there is no preference being expressed.<br clear="none"><br clear="none">That metadata is simply wrong.<div class="yiv9311727665yqt6134801023" id="yiv9311727665yqtfd84242"><br clear="none"><br clear="none">-- Scott<br clear="none"><br clear="none">-- <br clear="none">To unsubscribe from this list send an email to <a rel="nofollow" shape="rect" ymailto="mailto:users-unsubscribe@shibboleth.net" target="_blank" href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br clear="none"></div><br clear="none"><br clear="none"></div>  </div> </div>  </div></div></body></html>