<div dir="ltr">Has anyone used Shibboleth IDP 3 and the onelogin PHP SAML Library? We are trying to get it working for requesting the email attribute with the formatting of <span style="color:rgb(3,47,98);font-family:SFMono-Regular,Consolas,"Liberation Mono",Menlo,Courier,monospace;font-size:12px;white-space:pre">urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress but i'm getting this in the logs:</span><div><span style="color:rgb(3,47,98);font-family:SFMono-Regular,Consolas,"Liberation Mono",Menlo,Courier,monospace;font-size:12px;white-space:pre"><br></span></div><div><span style="color:rgb(3,47,98);font-family:SFMono-Regular,Consolas,"Liberation Mono",Menlo,Courier,monospace;font-size:12px;white-space:pre"><br></span></div><div><font color="#032f62" face="SFMono-Regular, Consolas, Liberation Mono, Menlo, Courier, monospace"><span style="white-space:pre">2017-06-21 16:02:17,521 - DEBUG [net.shibboleth.idp.saml.saml2.profile.impl.AddAttributeStatementToAssertion:116] - Profile Action AddAttributeStatementToAssertion: Adding constructed AttributeStatement to Assertion _2d5c96c50591b2ce8f913870584a02eb
2017-06-21 16:02:17,545 - DEBUG [org.opensaml.saml.saml2.profile.impl.AddNameIDToSubjects:286] - Profile Action AddNameIDToSubjects: Attempting to add NameID to outgoing Assertion Subjects
2017-06-21 16:02:17,545 - DEBUG [org.opensaml.saml.common.profile.logic.AbstractNameIDPolicyPredicate:218] - Policy checking disabled for NameIDPolicy with Format urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress
2017-06-21 16:02:17,545 - DEBUG [org.opensaml.saml.saml2.profile.impl.AddNameIDToSubjects:316] - Profile Action AddNameIDToSubjects: Request specified NameID format: urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress
2017-06-21 16:02:17,546 - DEBUG [org.opensaml.saml.saml2.profile.impl.AddNameIDToSubjects:396] - Profile Action AddNameIDToSubjects: Trying to generate NameID with Format urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress
2017-06-21 16:02:17,549 - DEBUG [org.opensaml.saml.common.profile.impl.ChainingNameIdentifierGenerator:106] - Trying to generate identifier with Format urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress
2017-06-21 16:02:17,549 - WARN [org.opensaml.saml.saml2.profile.impl.AddNameIDToSubjects:337] - Profile Action AddNameIDToSubjects: Request specified use of an unsupportable identifier format: urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress
2017-06-21 16:02:17,551 - WARN [org.opensaml.profile.action.impl.LogEvent:105] - A non-proceed event occurred while processing the request: InvalidNameIDPolicy
2017-06-21 16:02:17,551 - DEBUG [org.opensaml.saml.common.profile.logic.DefaultLocalErrorPredicate:184] - Error event InvalidNameIDPolicy will be handled with response
</span></font><br></div><div><br></div><div><div>2017-06-21 16:02:17,582 - DEBUG [net.shibboleth.idp.saml.profile.impl.SpringAwareMessageEncoderFactory:100] - Looking up message encoder based on binding URI: urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST</div><div>2017-06-21 16:02:17,582 - DEBUG [org.opensaml.saml.saml2.binding.encoding.impl.HTTPPostEncoder:159] - Invoking Velocity template to create POST body</div><div>2017-06-21 16:02:17,582 - DEBUG [org.opensaml.saml.saml2.binding.encoding.impl.HTTPPostEncoder:192] - Encoding action url of '<a href="https://app.">https://app.</a>*****/rest/saml/auth/682879' with encoded value 'https&#x3a;&#x2f;&#x2f;<a href="http://app.wheniwork.com">app.wheniwork.com</a>&#x2f;rest&#x2f;saml&#x2f;auth&#x2f;682879'</div><div>2017-06-21 16:02:17,583 - DEBUG [org.opensaml.saml.saml2.binding.encoding.impl.HTTPPostEncoder:198] - Marshalling and Base64 encoding SAML message</div><div>2017-06-21 16:02:17,584 - DEBUG [org.opensaml.saml.saml2.binding.encoding.impl.HTTPPostEncoder:220] - Setting RelayState parameter to: '<a href="https://app.">https://app.</a>*****/rest/saml/sso/682879', encoded as 'https&#x3a;&#x2f;&#x2f;<a href="http://deltaems.wheniwork.com">deltaems.wheniwork.com</a>&#x2f;rest&#x2f;saml&#x2f;sso&#x2f;682879'</div><div>2017-06-21 16:02:17,619 - DEBUG [PROTOCOL_MESSAGE:70] -</div><div><?xml version="1.0" encoding="UTF-8"?></div><div><saml2p:Response</div><div>    Destination="<a href="https://app.">https://app.</a>*****/rest/saml/auth/682879"</div><div>    ID="_287de7299ff7144786bdcbfc581aaae4"</div><div>    InResponseTo="ONELOGIN_dddba38cfe08ca53c64103a8dbd6ff8baa05330e"</div><div>    IssueInstant="2017-06-21T16:02:17.552Z" Version="2.0" xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol"></div><div>    <saml2:Issuer xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"><a href="https://ec2-52-205-175-9.compute-1.amazonaws.com/idp/shibboleth">https://ec2-52-205-175-9.compute-1.amazonaws.com/idp/shibboleth</a></saml2:Issuer></div><div>    <ds:Signature</div><div>                xmlns:ds="<a href="http://www.w3.org/2000/09/xmldsig#">http://www.w3.org/2000/09/xmldsig#</a>"></div><div><ds:SignedInfo></div><div><ds:CanonicalizationMethod</div><div>                Algorithm="<a href="http://www.w3.org/2001/10/xml-exc-c14n#">http://www.w3.org/2001/10/xml-exc-c14n#</a>"/></div><div><ds:SignatureMethod</div><div>                Algorithm="<a href="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256">http://www.w3.org/2001/04/xmldsig-more#rsa-sha256</a>"/></div><div><ds:Reference</div><div>                        URI="#_287de7299ff7144786bdcbfc581aaae4"></div><div><ds:Transforms></div><div><ds:Transform</div><div>                        Algorithm="<a href="http://www.w3.org/2000/09/xmldsig#enveloped-signature">http://www.w3.org/2000/09/xmldsig#enveloped-signature</a>"/></div><div><ds:Transform</div><div>                    Algorithm="<a href="http://www.w3.org/2001/10/xml-exc-c14n#">http://www.w3.org/2001/10/xml-exc-c14n#</a>"/></div><div></ds:Transforms></div><div><ds:DigestMethod Algorithm="<a href="http://www.w3.org/2001/04/xmlenc#sha256">http://www.w3.org/2001/04/xmlenc#sha256</a>"/></div><div><ds:DigestValue>WN33K1jzNaKquXb3/MNE9yKkv+rxxr9kaktp1b07nKk=</ds:DigestValue></div><div></ds:Reference></div><div></ds:SignedInfo></div><div><ds:SignatureValue></div><div>mBFhQFTAWEQiGk+j0IBVOy+qieXKl3zeoUlPumOdvjei9GFgZpaJO8B8RXkIMXyI5lAwF8ckkTPZ</div><div>suHZq1Il6xw9tLUmIREX64MGPfaJG3np8p+EG4UjpsIFV/6hNx8h9GJeAHjeua+4GCoJc9RKHuzB</div><div>EHAnmWCW9zDBfWCn/yz+1ERKfRmdNxOFIZDzdRUV4gBDPdtuvEdQ3+g8BpYg8ho8bQ9Zdf/JsJ1k</div><div>VjU6x8qwmJ8OmbKR5KHQg2vACt3Y66mmVSMmQWxx6B6J6QJcc0UTSqj1jlm5pKb0bwKsBo163hhI</div><div>JGe0pmR4STy7+RVGSC4oeUtity8OBnQE/LU06g==</div><div></ds:SignatureValue></div><div><ds:KeyInfo></div><div>            <ds:X509Data></div><div>                <ds:X509Certificate>MIIDjjCCAnagAwIBAgIVALZXVrIMahjLPgP5zCZ919nEWgKOMA0GCSqGSIb3DQEBCwUAMDMxMTAv</div><div>BgNVBAMMKGVjMi01Mi0yMDUtMTc1LTkuY29tcHV0ZS0xLmFtYXpvbmF3cy5jb20wHhcNMTcwNjIx</div><div>MTM1NDQyWhcNMzcwNjIxMTM1NDQyWjAzMTEwLwYDVQQDDChlYzItNTItMjA1LTE3NS05LmNvbXB1</div><div>dGUtMS5hbWF6b25hd3MuY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxdoGde96</div><div>+X7wsvaLgq/KIxDchSpBVCqaeaKMoZdaHZEoebVQI0NV0F845hCsLMauLAr1q3MpqPsPcbMflZ0F</div><div>y9fjP09ytGrB3R+0qbv1pqo+Fgc1XQKuAzQHNQjnJv2apA4fZdfe0PAa4T30aomGHnvAeZkwLAC7</div><div>aDnBTmYc9z4TysAPR+F6hTiBxyXpKzAsSC0+pTQI9Ed7/DwsRhY314QJL5FijLNSJxSyL0Z+JXq1</div><div>ZrK/EKr6G4d1jazeGm91Vo0YGKtoCoWwa9hXAg59LRY42sJcH3h0arZb8FnJLSbL2rDb9LyhBKgQ</div><div>x2zxmQCyhTK433iYeW36YogCrHws9QIDAQABo4GYMIGVMB0GA1UdDgQWBBRagN8EDWrdIixZXZ3M</div><div>U7XK1ThEzDB0BgNVHREEbTBrgihlYzItNTItMjA1LTE3NS05LmNvbXB1dGUtMS5hbWF6b25hd3Mu</div><div>Y29thj9odHRwczovL2VjMi01Mi0yMDUtMTc1LTkuY29tcHV0ZS0xLmFtYXpvbmF3cy5jb20vaWRw</div><div>L3NoaWJib2xldGgwDQYJKoZIhvcNAQELBQADggEBACK8wHHT0CCS738sSrovXLDsXzjPsQlLy+EE</div><div>BKzewpLEBh/Yu28d3AerbCqwfS9D3YDcIOcjCHSqVyU0ewaVZ2Iq1bo4ov+9B8EJb76lPX+YnnIr</div><div>/rHsQJygl7d7BzJchmSh8YJknKlfmxMfxCMNVuVo/3Q+K0vQeXxZQ5svLlFgSdGRSaTLO6UQqp2M</div><div>3uDs6SwsGDR+CpiUyke1wAcnBzVzMQ6lpRopylM1//mCi7pOmFBcG0e1qUeXRcp8nh/DYqpchind</div><div>w007/vN1hpEyhILhPW/xQgMcvxkdCJMsPYuM2U0GHQzP6AzY4LLXdIAK2icxY/prCd+u/CFWVqft</div><div>Qt0=</ds:X509Certificate></div><div>            </ds:X509Data></div><div>        </ds:KeyInfo></div><div>    </ds:Signature></div><div>    <saml2p:Status></div><div>        <saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Requester"></div><div>            <saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:InvalidNameIDPolicy"/></div><div>        </saml2p:StatusCode></div><div>        <saml2p:StatusMessage>An error occurred.</saml2p:StatusMessage></div><div>    </saml2p:Status></div><div></saml2p:Response></div><div><br></div><div>2017-06-21 16:02:17,620 - DEBUG [net.shibboleth.idp.profile.impl.RecordResponseComplete:89] - Profile Action RecordResponseComplete: Record response complete</div></div></div>