<div dir="ltr"><div>Thanks Scott. I ll read on the docs... but here the log... apparently it did try to use that format :</div><div><br></div><div><br></div><div>2017-03-26 18:26:22,388 - DEBUG [org.opensaml.saml.saml2.profile.impl.AddNameIDToSubjects:341] - Profile Action AddNameIDToSubjects: Unable to generate a NameID, leaving empty</div><div> 2017-03-26 18:26:22,388 - DEBUG [org.opensaml.saml.common.profile.impl.ChainingNameIdentifierGenerator:106] - Trying to generate identifier with Format urn:oasis:names:tc:SAML:1.1:nameid-format:emaintNameid"</div><div> 2017-03-26 18:26:22,387 - DEBUG [org.opensaml.saml.saml2.profile.impl.AddNameIDToSubjects:396] - Profile Action AddNameIDToSubjects: Trying to generate NameID with Format urn:oasis:names:tc:SAML:1.1:nameid-format:emaintNameid"</div><div> 2017-03-26 18:26:22,386 - DEBUG [org.opensaml.saml.saml2.profile.impl.AddNameIDToSubjects:323] - Profile Action AddNameIDToSubjects: Candidate NameID formats: [urn:oasis:names:tc:SAML:1.1:nameid-format:emaintNameid"]</div><div> 2017-03-26 18:26:22,385 - DEBUG [net.shibboleth.idp.saml.profile.logic.DefaultNameIdentifierFormatStrategy:137] - Configuration did not specify any formats, relying on metadata alone</div><div> 2017-03-26 18:26:22,385 - DEBUG [net.shibboleth.idp.saml.profile.logic.DefaultNameIdentifierFormatStrategy:124] - Configuration specifies the following formats: []</div><div> 2017-03-26 18:26:22,384 - DEBUG [org.opensaml.saml.common.profile.logic.MetadataNameIdentifierFormatStrategy:82] - Metadata specifies the following formats: [urn:oasis:names:tc:SAML:1.1:nameid-format:emaintNameid"]</div><div> 2017-03-26 18:26:22,384 - DEBUG [org.opensaml.saml.common.profile.logic.AbstractNameIDPolicyPredicate:218] - Policy checking disabled for NameIDPolicy with Format urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified</div><div><br></div><div><br></div></div><div class="gmail_extra"><br><div class="gmail_quote">On Sun, Mar 26, 2017 at 4:07 PM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">On 3/26/17, 3:36 PM, "users on behalf of Mohamed Lrhazi" <<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:lrhazi@cua.edu">lrhazi@cua.edu</a>> wrote:<br>
<br>
> am trying to force Assertion/Subject/NameID to be the CN of the user, as requested by the SP....<br>
> I tried adding a custom format in the SP metadata:<br>
<br>
</span>You have no standing to make up names in the OASIS namespace, so please don't. That is invalid.<br>
<br>
In other respects, there's nothing wrong mechanically with your approach.<br>
<span class=""><br>
> The NameID though is left empty:<br>
<br>
</span>Then the system probably didn't select that Format to use, and you need to read the documentation on Format selection. You left out ample logging that would have shown that clearly.<br>
<span class="HOEnZb"><font color="#888888"><br>
-- Scott<br>
<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br>
</font></span></blockquote></div><br></div>