<div dir="ltr">Hello,<div><br></div><div>I'm looking to clean this up but I have some questions, when someone has a moment.</div><div><br></div><div>This is what it looks like I need to do - but I am unsure about some things.</div><div><br></div><div>1. Uncomment this line in saml-nameid.properties:</div><div><br></div><blockquote style="margin:0 0 0 40px;border:none;padding:0px"><div><div>#idp.transientId.generator = shibboleth.CryptoTransientIdGenerator</div></div></blockquote><div> </div><div>  Question: What about these lines? Should they also be uncommented?</div><div><br></div><blockquote style="margin:0 0 0 40px;border:none;padding:0px"><div><div># Default NameID formats to use when nothing else is called for</div></div><div><div>#idp.nameid.saml2.default = urn:oasis:names:tc:SAML:2.0:nameid-format:transient</div></div><div><div>#idp.nameid.saml1.default = urn:mace:shibboleth:1.0:nameIdentifier</div></div></blockquote><div><br></div><div>2. Remove/comment out this section of the attribute-resolver file:</div><div><br></div><blockquote style="margin:0 0 0 40px;border:none;padding:0px"><div><div><resolver:AttributeDefinition id="transientId" xsi:type="ad:TransientId"></div></div><div><div>        <resolver:AttributeEncoder xsi:type="enc:SAML1StringNameIdentifier" nameFormat="urn:mace:shibboleth:1.0:nameIdentifier" /></div></div><div><div>        <resolver:AttributeEncoder xsi:type="enc:SAML2StringNameID" nameFormat="urn:oasis:names:tc:SAML:2.0:nameid-format:transient" /></div></div><div><div>    </resolver:AttributeDefinition></div></div></blockquote><div><div><br></div><div>3. Do I need to put anything additional in the saml-nameid.xml file to actually generate the transientId? If not, I don't see where it actually gets the name 'transientId' (unless it's built in.)</div><div><br></div><div>4. Do you control its release it in the attribute-filter file still when you use this new method? Or is that handled by the 'default NameID formats" section (above)?</div><div><br></div><div>Sorry to be confused! I have a number of customized nameid's in my saml-nameid.xml file but they all have source attributes, of course, so I'm not really sure how this special case works.</div><div><br></div><div>Thank you,</div><div>Karla B</div><div><br></div>-- <br><div class="gmail_signature"><div style="margin-left:40px">Karla Borecky<br>Systems Administrator<br>ITS<br>Smith College<br>Northampton, MA 01063<br></div></div>
</div></div>