<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:#0563C1;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:#954F72;
text-decoration:underline;}
span.EmailStyle17
{mso-style-type:personal-compose;
font-family:"Calibri",sans-serif;
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="#0563C1" vlink="#954F72">
<div class="WordSection1">
<p class="MsoNormal">I’m in the home stretch on our IdP 2 -> 3 upgrade, and I’m trying to enable the persistentId NameID. Need a little help on tracking down a bug. I’ve searched the Jira tracker and the mailing list but haven’t found anything like this.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">I uncommented the line in saml-nameid.xml and added the attribute and salt to the saml-nameid.properties file. Reloading the NameIdentifierGeneratorService gives me this error:<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in">org.springframework.beans.MethodInvocationException: Property 'salt' threw exception;<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in">nested exception is net.shibboleth.utilities.java.support.logic.ConstraintViolationException: Salt cannot be null or empty<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><o:p> </o:p></p>
<p class="MsoNormal">Here is the sanitized properties file. I clearly have a string in the salt property:<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"># For computed IDs, set a source attribute and a secret salt:<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in">idp.persistentId.sourceAttribute = uid<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in">idp.persistentId.useUnfilteredAttributes = true<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"># Do *NOT* share the salt with other people, it's like divulging your private key.<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in">idp.persistentId.algorithm = SHA<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in">idp.persistentId.salt = *********************<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">saml-nameid.xml:<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"> <!-- SAML 2 NameID Generation --><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"> <util:list id="shibboleth.SAML2NameIDGenerators"><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-left:.5in"> <ref bean="shibboleth.SAML2TransientGenerator" /><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-left:.5in"> <!-- Uncommenting this bean requires configuration in saml-nameid.properties. --><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"> <ref bean="shibboleth.SAML2PersistentGenerator" /><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-left:.5in"> <bean parent="shibboleth.SAML2AttributeSourcedGenerator"<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"> p:format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress"<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"> p:attributeSourceIds="#{ {'mail'} }" /><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-left:.5in"> </util:list><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Any thoughts? I can go back to the V2 way (creating an eduPersonTargetedID from a computedID data connector in attribute-resolver.xml and using that in a SourcedGenerator like the email address NameID) but I’d rather stick with the V3 methodology
going forward.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Thanks,<o:p></o:p></p>
<p class="MsoNormal">Mark<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><b>Mark McCoy<o:p></o:p></b></p>
<p class="MsoNormal"><i><span style="font-size:10.0pt">OIT Manager – Platform Application Services<o:p></o:p></span></i></p>
<p class="MsoNormal"><i><span style="font-size:10.0pt">Office of Information Technology<o:p></o:p></span></i></p>
<p class="MsoNormal"><i><span style="font-size:10.0pt">The University of Texas at San Antonio<o:p></o:p></span></i></p>
<p class="MsoNormal"><i><span style="font-size:10.0pt">210-458-5871<o:p></o:p></span></i></p>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
</body>
</html>