<div dir="ltr"><div class="gmail_extra"><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr"><div class="gmail_extra"><div class="gmail_quote"><span class="">On Wed, Aug 31, 2016 at 1:18 PM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span>On 8/31/16, 1:08 PM, "users on behalf of Michael Dahlberg" <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:olgamirth@gmail.com" target="_blank">olgamirth@gmail.com</a>> wrote:<br>
<br>
> On a related note, is the option to encrypt/not encrypt the nameID different when using<br>
> Unsolicited SSO?<br>
<br>
</span>Nope.<br>
<span><br>
> The reason I ask is because in the bean for this entityId in the relying-party file, I<br>
> have the following line:<br>
<br>
</span>That's the default, so there's no reason to do that.<br>
<span><br>
> Unfortunately, the nameId looks like its still being encrypted<br>
<br>
</span>I can guarantee you it's not. Transient IDs are not encrypted, they're simply not readable.<br>
<div><div><br><br></div></div></blockquote><div><br></div></span><div>My apologies; its actually a persistent ID. Does that make a difference?</div></div></div></div></blockquote><div><br></div><div>Also, its a computed ID and the source attribute is returned correctly via LDAP as shown in the log files and specified in the saml-nameid.properties file.</div><div><br></div><div>Mike</div></div><br></div></div>