<div dir="ltr">> On top of all that, you're perhaps not understanding how Format selection happens <br><div><br></div><div>Heh, that's an understatement. I basically just followed the documentation from some other SP's to get them working. Oh well, thanks anyway.</div><div><br></div><div>Jason</div><div><br></div></div><br><div class="gmail_quote"><div dir="ltr">On Mon, Oct 1, 2018 at 4:40 PM Cantor, Scott <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">On 10/1/18, 4:31 PM, "users on behalf of Jason Rotunno" <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:jrotunno@swarthmore.edu" target="_blank">jrotunno@swarthmore.edu</a>> wrote:<br>
<br>
> We're running Shibboleth 3.3.x and in the past I've setup several SP's to use persistent IDs. For example:<br>
<br>
You made up your own Format (which is invalid, you can't make up an OASIS URN), actually and that's not a suitable value for an actual SAML 2.0 persistent NameID. So that's a problem on two counts.<br>
<br>
> p:format="urn:oasis:names:tc:SAML:1.1:nameid-format:persistent"<br>
<br>
That 1.1 should be 2.0 if you're talking about the Format defined in the standard, and that has to be an opaque pairwise value, not something like an employee ID.<br>
<br>
> employeeID as defined in conf/attribute-resolver.xml<br>
<br>
That's the deprecated way of encoding a NameID that duplicates the other part of the configuration you posted (and still has the wrong Format). But they're equivalent and the deprecated one won't matter, it's just duplicating the other stuff.<br>
<br>
>* Am I correct that the c:candidate value in conf/saml-nameid.xml should be the entityID in the SP's metadata?<br>
<br>
That's not the conventional way to control data release, though it's possible and sometimes useful. Normally the underlying attribute(s) get released with a filter rule and the rest is left alone as generic definitions of what's possible. If I can't get "mail", I can't get a NameID that's built on top of it, and it's all fine. With persistent NameIDs (real ones, not yours) it's a bit more complex and it depends which services you're willing to release them to and why.<br>
<br>
On top of all that, you're perhaps not understanding how Format selection happens, which is a separate issue and ultimately determines what it will try to do when the time comes to generate something and that's why it's just defaulting to transient. There's nothing there to tell it to do anything else.<br>
<br>
-- Scott<br>
<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div><br clear="all"><div><br></div>-- <br><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><pre cols="72">Jason Rotunno
System & Security Administrator
Swarthmore College
500 College Ave
Swarthmore, PA 19081
610.328.8505<br></pre><pre cols="72">Think BEFORE You Click!! Emails from Swarthmore College ITS won't be in your
Quarantine or Spam folder. We won't threaten you either! If you
receive any phishing emails, please forward them to <a href="mailto:phishing@swarthmore.edu" target="_blank">phishing@swarthmore.edu</a>.<br></pre></div></div></div></div></div>