<html>
<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>

<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:Wingdings;
        panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Consolas;
        panose-1:2 11 6 9 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
h1
        {mso-style-priority:9;
        mso-style-link:"Heading 1 Char";
        mso-margin-top-alt:auto;
        margin-right:0in;
        mso-margin-bottom-alt:auto;
        margin-left:0in;
        font-size:24.0pt;
        font-family:"Times New Roman",serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:#0563C1;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:#954F72;
        text-decoration:underline;}
code
        {mso-style-priority:99;
        font-family:"Courier New";}
span.EmailStyle17
        {mso-style-type:personal-compose;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
span.Heading1Char
        {mso-style-name:"Heading 1 Char";
        mso-style-priority:9;
        mso-style-link:"Heading 1";
        font-family:"Times New Roman",serif;
        font-weight:bold;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-family:"Calibri",sans-serif;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
/* List Definitions */
@list l0
        {mso-list-id:1781752477;
        mso-list-template-ids:-626614012;}
@list l0:level1
        {mso-level-number-format:bullet;
        mso-level-text:\F0B7;
        mso-level-tab-stop:1.0in;
        mso-level-number-position:left;
        margin-left:1.0in;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
@list l0:level2
        {mso-level-number-format:bullet;
        mso-level-text:\F0B7;
        mso-level-tab-stop:1.5in;
        mso-level-number-position:left;
        margin-left:1.5in;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Symbol;}
@list l0:level3
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:2.0in;
        mso-level-number-position:left;
        margin-left:2.0in;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l0:level4
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:2.5in;
        mso-level-number-position:left;
        margin-left:2.5in;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l0:level5
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:3.0in;
        mso-level-number-position:left;
        margin-left:3.0in;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l0:level6
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:3.5in;
        mso-level-number-position:left;
        margin-left:3.5in;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l0:level7
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:4.0in;
        mso-level-number-position:left;
        margin-left:4.0in;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l0:level8
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:4.5in;
        mso-level-number-position:left;
        margin-left:4.5in;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
@list l0:level9
        {mso-level-number-format:bullet;
        mso-level-text:\F0A7;
        mso-level-tab-stop:5.0in;
        mso-level-number-position:left;
        margin-left:5.0in;
        text-indent:-.25in;
        mso-ansi-font-size:10.0pt;
        font-family:Wingdings;}
ol
        {margin-bottom:0in;}
ul
        {margin-bottom:0in;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="#0563C1" vlink="#954F72">
<div class="WordSection1">
<h1 style="mso-margin-top-alt:0in;margin-right:0in;margin-bottom:15.0pt;margin-left:0in;background:white">
<span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D;font-weight:normal">I write to understand apparent inconsistencies in the Shibboleth wiki concerning persistent NameIDs for federating a Shibboleth IDP with Microsoft Azure. Perhaps
 I could help revise the documentation. <o:p></o:p></span></h1>
<h1 style="mso-margin-top-alt:0in;margin-right:0in;margin-bottom:15.0pt;margin-left:0in;background:white">
<span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D;font-weight:normal">(I would also like to resolve why Azure is rejecting the SAML assertions my Shibboleth IDP is sending, although these are properly formed according to “</span><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:black;font-weight:normal">Use
 a SAML 2.0 identity provider to implement single sign-on” in the section titled “Sample SAML Request and Response Messages,” at  </span><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D;font-weight:normal"><a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__msdn.microsoft.com_en-2Dus_library_azure_dn641269.aspx&d=BQMFAg&c=mRWFL96tuqj9V0Jjj4h40ddo0XsmttALwKjAEOCyUjY&r=UYqeRnATD1bRrzKAwbwX1u5kx7clpB4nZrMo7iddnDo&m=977vwIgZlwZBL9Ib3Y1UbauELVCy9odRQRAhvs0CuQY&s=cBul2deoqn7jnK1Up_4SzRNJ-BfV7ZFUO9WXQSbISbo&e=">https://msdn.microsoft.com/en-us/library/azure/dn641269.aspx</a>)<o:p></o:p></span></h1>
<p class="MsoNormal"><span style="color:#1F497D">***<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D">In <a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.shibboleth.net_confluence_display_IDP30_Office-26-2343-3B365&d=BQMFAg&c=mRWFL96tuqj9V0Jjj4h40ddo0XsmttALwKjAEOCyUjY&r=UYqeRnATD1bRrzKAwbwX1u5kx7clpB4nZrMo7iddnDo&m=977vwIgZlwZBL9Ib3Y1UbauELVCy9odRQRAhvs0CuQY&s=qXxWHjmJcSSr9AbOikOHBko6K_VmypfvUgunJRqPZPU&e=">
https://wiki.shibboleth.net/confluence/display/IDP30/Office+365</a>  concerning the configuration of conf/attribute-resolver.xml (section 4), we read<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal" style="line-height:15.0pt;background:white"><span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:#333333">“Another attribute definition is typically required in order to send the Azure ImmutableID in the SAML Subject.  The
 ImmutableID attribute is site dependent, but most frequently maps to the "objectGuid" in Active Directory.”<o:p></o:p></span></p>
<p class="MsoNormal" style="line-height:15.0pt;background:white"><span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:#333333"><o:p> </o:p></span></p>
<p class="MsoNormal" style="margin-top:7.5pt;line-height:15.0pt;background:white">
<span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:#333333">There appears to be no explicit mapping of ImmutableID—this identifier occurs only in the remarks at section 4  in
<a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.shibboleth.net_confluence_display_IDP30_Office-26-2343-3B365&d=BQMFAg&c=mRWFL96tuqj9V0Jjj4h40ddo0XsmttALwKjAEOCyUjY&r=UYqeRnATD1bRrzKAwbwX1u5kx7clpB4nZrMo7iddnDo&m=977vwIgZlwZBL9Ib3Y1UbauELVCy9odRQRAhvs0CuQY&s=qXxWHjmJcSSr9AbOikOHBko6K_VmypfvUgunJRqPZPU&e=">https://wiki.shibboleth.net/confluence/display/IDP30/Office+365</a>.<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-top:7.5pt;line-height:15.0pt;background:white">
<span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:#333333">The example at 4 shows the identifier “</span><span style="font-size:10.5pt;font-family:Consolas;color:#003366;background:white">uMemphisAdObjectGuid” both as the attribute id and the
 source within a directory. [In my implementation, I follow <a href="https://urldefense.proofpoint.com/v2/url?u=http-3A__idmoim.blogspot.com_2015_02_office-2D365-2Dintegrating-2Dwith-2Dshibboleth.html&d=BQMFAg&c=mRWFL96tuqj9V0Jjj4h40ddo0XsmttALwKjAEOCyUjY&r=UYqeRnATD1bRrzKAwbwX1u5kx7clpB4nZrMo7iddnDo&m=977vwIgZlwZBL9Ib3Y1UbauELVCy9odRQRAhvs0CuQY&s=3E_WwkbdXVOutFMHnjUzbgH7UeHQeSNeI_uKPehzp_E&e=">
http://idmoim.blogspot.com/2015/02/office-365-integrating-with-shibboleth.html</a>, in which the id is ImmutableID and the source is objectGUID. My data connector has the line
</span><span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:#333333"><o:p></o:p></span></p>
<p class="MsoNormal" style="margin-top:7.5pt;line-height:15.0pt;background:white">
<span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:#333333"><dc:LDAPProperty name="java.naming.ldap.attributes.binary" value="objectGUID"/><o:p></o:p></span></p>
<p class="MsoNormal" style="margin-top:7.5pt;line-height:15.0pt;background:white">
<span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:#333333">to ensure that the objectGUID is Base64 encoded—omit it and the objectGUID is transmitted in binary.  This seems to be the intention of the parenthetical remark concerning encoding
 in the comment “</span><span style="font-size:10.5pt;font-family:Consolas;color:#008200;background:white"><!-- Needed Office365 Integration. Used for NameID value. (No encoder necessary) -->”
</span><span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:#333333">  at section 4.
<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-top:7.5pt;line-height:15.0pt;background:white">
<span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:#333333">Note also that the attribute ‘NameID’ occurs for the first time in this comment—its relation to ‘ImmutableID’ is unclear.  Incidentally, Microsoft’s documentation at
<a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__technet.microsoft.com_en-2Dus_library_jj205463-23BKMK-5F1&d=BQMFAg&c=mRWFL96tuqj9V0Jjj4h40ddo0XsmttALwKjAEOCyUjY&r=UYqeRnATD1bRrzKAwbwX1u5kx7clpB4nZrMo7iddnDo&m=977vwIgZlwZBL9Ib3Y1UbauELVCy9odRQRAhvs0CuQY&s=fTh85235Fzi30MMTTFtzjLCU3X_8IyapMaSMG5CYBAo&e=">https://technet.microsoft.com/en-us/library/jj205463#BKMK_1</a> omits the xml namespace identifier ‘dc’ in ‘dc:LDAPProperty’. ]<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-top:7.5pt;line-height:15.0pt;background:white">
<span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:#333333">It’s the NameID value that seems confusing to me, since this appears to have two sources: attribute-resolver.xml, and saml-nameid.xml together with saml.nameid-properties.<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-top:7.5pt;line-height:15.0pt;background:white">
<span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:#333333">***<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-top:7.5pt;line-height:15.0pt;background:white">
<span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:#333333"><o:p> </o:p></span></p>
<p class="MsoNormal">Our attribute resolver uses the Active Directory object source attribute objectGUID and renames it as ImmutableID. <span style="font-size:12.0pt;font-family:"Times New Roman",serif"><o:p></o:p></span></p>
<p class="MsoNormal">In saml-nameid.xml in my implementation, the ImmutableID is used to produce a NameID, and this is passed to the SAML assertion to Microsoft (I don’t pretend to understand the mechanism, but this is what my firefox SAML trace reports). The
 relevant code from saml-nameid.xml is here:<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><!-- Microsoft requires a custom Persistent ID Generator that sends the AD GUID --><o:p></o:p></p>
<p class="MsoNormal">   <bean parent="shibboleth.SAML2AttributeSourcedGenerator"<o:p></o:p></p>
<p class="MsoNormal">        p:format="urn:oasis:names:tc:SAML:2.0:nameid-format:persistent"<o:p></o:p></p>
<p class="MsoNormal">        p:attributeSourceIds="#{ {'ImmutableID'} }"><o:p></o:p></p>
<p class="MsoNormal">    <property name="activationCondition">      <o:p></o:p></p>
<p class="MsoNormal">        <bean parent="shibboleth.Conditions.RelyingPartyId" c:candidates="#{{'urn:federation:MicrosoftOnline'}}" /><o:p></o:p></p>
<p class="MsoNormal">     </property><o:p></o:p></p>
<p class="MsoNormal">  </bean><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">However, there are properties in same-named.properties (not mentioned at
<a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.shibboleth.net_confluence_display_IDP30_Office-26-2343-3B365&d=BQMFAg&c=mRWFL96tuqj9V0Jjj4h40ddo0XsmttALwKjAEOCyUjY&r=UYqeRnATD1bRrzKAwbwX1u5kx7clpB4nZrMo7iddnDo&m=977vwIgZlwZBL9Ib3Y1UbauELVCy9odRQRAhvs0CuQY&s=qXxWHjmJcSSr9AbOikOHBko6K_VmypfvUgunJRqPZPU&e=">https://wiki.shibboleth.net/confluence/display/IDP30/Office+365</a>) that, in our case, take objectGUID and produce a hashed value based on a salt.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">What is the difference between this computed value and the ImmutableID? Why does the unhashed base64 value of objectGUID appear as NameID in the SAML assertion? What happened to the hashed value set in saml-namid.xml? Where is it used?
 Which should be used so that logins will work?<o:p></o:p></p>
<p class="MsoNormal" style="margin-top:7.5pt;line-height:15.0pt;background:white">
<span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:#333333">[I could send the SAML assertions.]<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-top:7.5pt;line-height:15.0pt;background:white">
<span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:#333333"><o:p> </o:p></span></p>
<p class="MsoNormal" style="margin-top:7.5pt;line-height:15.0pt;background:white">
<span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:#333333">***<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-top:7.5pt;line-height:15.0pt;background:white">
<span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:#333333"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:#333333">The Shibboleth wiki page
</span><a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.shibboleth.net_confluence_display_IDP30_PersistentNameIDGenerationConfiguration&d=BQMFAg&c=mRWFL96tuqj9V0Jjj4h40ddo0XsmttALwKjAEOCyUjY&r=UYqeRnATD1bRrzKAwbwX1u5kx7clpB4nZrMo7iddnDo&m=977vwIgZlwZBL9Ib3Y1UbauELVCy9odRQRAhvs0CuQY&s=pnIkrGmbPJsIBtlmXYooA15Zu9hpnvb6EawYXoGPQbE&e="><span style="color:#333333">PersistentNameIDGenerationConfiguration</span></a><span style="background:white"> at </span><span style="font-size:12.0pt;background:white"><o:p></o:p></span></p>
<p class="MsoNormal"><span style="background:white"><a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.shibboleth.net_confluence_display_IDP30_PersistentNameIDGenerationConfiguration&d=BQMFAg&c=mRWFL96tuqj9V0Jjj4h40ddo0XsmttALwKjAEOCyUjY&r=UYqeRnATD1bRrzKAwbwX1u5kx7clpB4nZrMo7iddnDo&m=977vwIgZlwZBL9Ib3Y1UbauELVCy9odRQRAhvs0CuQY&s=pnIkrGmbPJsIBtlmXYooA15Zu9hpnvb6EawYXoGPQbE&e=">https://wiki.shibboleth.net/confluence/display/IDP30/PersistentNameIDGenerationConfiguration</a>,
</span> which raises more questions than it answers; <span style="font-size:10.5pt;color:black">
advises against using objectGUID for a persistent NameID (in case the AD changes). See the highlighted text below.</span><span style="font-family:"Times New Roman",serif"><o:p></o:p></span></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;margin-left:0in;text-indent:-.25in;line-height:15.0pt;mso-list:l0 level1 lfo1">
<![if !supportLists]><span style="font-size:10.0pt;font-family:Symbol;color:#333333"><span style="mso-list:Ignore">·<span style="font:7.0pt "Times New Roman"">        
</span></span></span><![endif]><strong><span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:#333333;background:white">idp.persistentId.sourceAttribute</span></strong><span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:#333333"><o:p></o:p></span></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;margin-left:0in;text-indent:-.25in;line-height:15.0pt;mso-list:l0 level2 lfo1">
<![if !supportLists]><span style="font-size:10.0pt;font-family:Symbol;color:#333333"><span style="mso-list:Ignore">·<span style="font:7.0pt "Times New Roman"">        
</span></span></span><![endif]><span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:#333333;background:white">A list of attributes from which to derive a "source" key for the subject. The key is used as the hash input, and should be a very stable
 value for each subject and must <strong><span style="font-family:"Arial",sans-serif">never</span></strong> be reassigned later to a different subject. This should be a permanent serial number associated by an IDMS to each account, and not a name-based identifier
 like a login ID or email address. It should also be technology-neutral.</span><span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:#333333;background:yellow"> Using a GUID generated by an Active DIrectory is a very bad choice that will lead to
 problems if you ever change directories.</span><span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:#333333"><o:p></o:p></span></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;margin-left:1.0in;line-height:15.0pt">
<span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:#333333"><o:p> </o:p></span></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;margin-left:1.0in;line-height:15.0pt">
<span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:#333333"><o:p> </o:p></span></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;margin-left:0in;text-indent:-.25in;line-height:15.0pt;mso-list:l0 level1 lfo1">
<![if !supportLists]><span style="font-size:10.0pt;font-family:Symbol;color:#333333"><span style="mso-list:Ignore">·<span style="font:7.0pt "Times New Roman"">        
</span></span></span><![endif]><span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:#333333">We do have an alternative to objectGUID (an employeeID that stays with the subject, as opposed to some specific object representing the subject in a particular
 AD), but it is fair to say there is some tension between this recommendation and the remarks in section 4 of
</span><span style="color:#1F497D"><a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.shibboleth.net_confluence_display_IDP30_Office-26-2343-3B365&d=BQMFAg&c=mRWFL96tuqj9V0Jjj4h40ddo0XsmttALwKjAEOCyUjY&r=UYqeRnATD1bRrzKAwbwX1u5kx7clpB4nZrMo7iddnDo&m=977vwIgZlwZBL9Ib3Y1UbauELVCy9odRQRAhvs0CuQY&s=qXxWHjmJcSSr9AbOikOHBko6K_VmypfvUgunJRqPZPU&e=">https://wiki.shibboleth.net/confluence/display/IDP30/Office+365</a>. 
</span><span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:#333333"><o:p></o:p></span></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;line-height:15.0pt">
<span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:#333333">[For now, let’s stick with objectGUID; whatever is supposed to be the source of NameID will still be subject to the same questions and considerations, independently of whether an identifier
 tracks a subject as opposed to a particular object representation of a subject in some specific directory.]<o:p></o:p></span></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;margin-left:0in;text-indent:-.25in;line-height:15.0pt;mso-list:l0 level1 lfo1">
<![if !supportLists]><span style="font-size:10.0pt;font-family:Symbol;color:#333333"><span style="mso-list:Ignore">·<span style="font:7.0pt "Times New Roman"">        
</span></span></span><![endif]><span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:#333333">Syntactically, how is the list represented? What semantic and syntactic relations, if any, does
<strong><span style="font-family:"Arial",sans-serif;background:white">idp.persistentId.sourceAttribute</span></strong> in saml-nameid.properties have to the line
<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-top:7.5pt;line-height:15.0pt;background:white">
p:attributeSourceIds="#{ {'ImmutableID'} }" <span style="font-size:12.0pt;font-family:"Times New Roman",serif">
<o:p></o:p></span></p>
<p class="MsoNormal" style="margin-top:7.5pt;line-height:15.0pt;background:white">
in saml-named.xml? The comment in saml-nameid.properties states<o:p></o:p></p>
<p class="MsoNormal" style="margin-top:7.5pt;line-height:15.0pt;background:white">
“# For computed IDs, set a source attribute and a secret salt:” which seems to indicate that the argument is a single attribute and not a list.<o:p></o:p></p>
<p class="MsoNormal" style="margin-top:7.5pt;line-height:15.0pt;background:white">
<o:p> </o:p></p>
<p class="MsoNormal" style="margin-top:7.5pt;line-height:15.0pt;background:white">
Finally, the property  <b>idp.persistentId.useUnfilteredAttributes</b>, which is defaulted to the value true, according to the comment in saml-nameid.properties. This setting would appear to bypass the filtering in section 5 of  <span style="color:#1F497D"><a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.shibboleth.net_confluence_display_IDP30_Office-26-2343-3B365&d=BQMFAg&c=mRWFL96tuqj9V0Jjj4h40ddo0XsmttALwKjAEOCyUjY&r=UYqeRnATD1bRrzKAwbwX1u5kx7clpB4nZrMo7iddnDo&m=977vwIgZlwZBL9Ib3Y1UbauELVCy9odRQRAhvs0CuQY&s=qXxWHjmJcSSr9AbOikOHBko6K_VmypfvUgunJRqPZPU&e=">https://wiki.shibboleth.net/confluence/display/IDP30/Office+365</a>
 concerning the configuration of attribute-filter.xml. <o:p></o:p></span></p>
<p class="MsoNormal" style="margin-top:7.5pt;line-height:15.0pt;background:white">
<span style="color:#1F497D">(The example there switches to a version of the syntax prior to the version of my implementation, which is 3.2.1. In the example at section 5, the syntax
</span><code><span style="font-size:10.5pt;font-family:Consolas;border:none windowtext 1.0pt;padding:0in;background:white">xsi:type="basic:AttributeRequesterString" becomes xsi:type="Requester", following
<a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.shibboleth.net_confluence_display_IDP30_AttributeFilterLegacyNameSpaceMapping&d=BQMFAg&c=mRWFL96tuqj9V0Jjj4h40ddo0XsmttALwKjAEOCyUjY&r=UYqeRnATD1bRrzKAwbwX1u5kx7clpB4nZrMo7iddnDo&m=977vwIgZlwZBL9Ib3Y1UbauELVCy9odRQRAhvs0CuQY&s=dK_1MPgEsxKoXk4XyX1hV4UMCWu-N6D0-H01X89eqMU&e=">
https://wiki.shibboleth.net/confluence/display/IDP30/AttributeFilterLegacyNameSpaceMapping</a>. This is not an issue, however.)<o:p></o:p></span></code></p>
<p class="MsoNormal" style="margin-top:7.5pt;line-height:15.0pt;background:white">
<span style="font-size:12.0pt;font-family:"Times New Roman",serif"><o:p> </o:p></span></p>
<p class="MsoNormal" style="margin-top:7.5pt;line-height:15.0pt;background:white">
Thanks,<o:p></o:p></p>
<p class="MsoNormal" style="margin-top:7.5pt;line-height:15.0pt;background:white">
<o:p> </o:p></p>
<p class="MsoNormal">Florian Lengyel<o:p></o:p></p>
<p class="MsoNormal">CUNY Computing and Information Services<o:p></o:p></p>
<p class="MsoNormal">395 Hudson Street, 6-247, New York, NY 10014<o:p></o:p></p>
<p class="MsoNormal">646 664-2370, Florian.Lengyel@cuny.edu<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
</body>
</html>