<div dir="ltr"><font color="#000000" face="arial, helvetica, sans-serif">I have two encoders in the resolver for the eduPersonUniqueID SAML attribute I'm trying to use for nameID: </font><div><font color="#000000" face="arial, helvetica, sans-serif">1) "normal" <span style="font-variant-ligatures:no-common-ligatures;font-size:11px">SAML2ScopedString </span>encoder</font></div>
<div><font color="#000000" face="arial, helvetica, sans-serif">2) <span style="font-variant-ligatures:no-common-ligatures;font-size:11px">SAML2StringNameID encoder for use as subject</span></font></div><div><font face="arial, helvetica, sans-serif"><br></font></div><div><font face="arial, helvetica, sans-serif">Is that trying to be too clever? Do I have to define a new SAML attribute with just the nameID encoding?</font></div><div><font face="arial, helvetica, sans-serif"><br></font></div><div><font face="arial, helvetica, sans-serif">David</font></div>
<div class="gmail_extra"><font face="arial, helvetica, sans-serif"><br></font><div class="gmail_quote"><font face="arial, helvetica, sans-serif">On Mon, Sep 11, 2017 at 4:30 PM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br></font><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><font face="arial, helvetica, sans-serif"><span class="">On 9/11/17, 7:34 PM, "users on behalf of Klingenstein, Nate" <<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:nklingenstein@calstate.edu">nklingenstein@calstate.edu</a>> wrote:<br>
<br>
> I typically get that message when the IdP is trying to generate a NameID, but it's unable to do so because I'm not releasing an<br>
> attribute that meets the requirements of the request.<br>
<br>
</span>That of course is true but he had a release rule and I assumed that was checked.<br>
<span class=""><br>
> Whether you're using actual persistentId's with other SP's, I don't know, but you'll probably need to define something in saml-<br>
> nameid.xml for this if it's going to use the actual NameID signaling.<br>
<br>
</span>The formal selection process works the same whether you're generating them the way it's done now or using the legacy fallback to the resolver and its AttributeEncoders. It's just that the legacy generation is controlled with a property and can be turned off to prevent accidental use of a deprecated method, and it probably defaults to being "off" on a new install.<br>
</font><div class="HOEnZb"><div class="h5"><font face="arial, helvetica, sans-serif"><br>
-- Scott<br>
<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br>
</font></div></div></blockquote></div><br></div></div>