<div dir="ltr"><div dir="ltr">Thanks for the Debug suggestion Art.<div><br></div><div>The NameID is what I am expecting.</div><div><br></div><div><div><saml2p:Status></div><div> <saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success"/></div><div> </saml2p:Status></div><div> <saml2:Assertion ID="_c9c586616dbc6094036b76969a6f784f"</div><div> IssueInstant="2019-05-20T21:34:57.637Z" Version="2.0" xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"></div><div> <saml2:Issuer><a href="https://idp-389ds-test.everettcc.edu/idp/shibboleth">https://idp-389ds-test.everettcc.edu/idp/shibboleth</a></saml2:Issuer></div><div> <saml2:Subject></div><div> <b><i> <saml2:NameID</i></b></div><div><b><i> Format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"</i></b></div><div><b><i> NameQualifier="<a href="https://idp-389ds-test.everettcc.edu/idp/shibboleth">https://idp-389ds-test.everettcc.edu/idp/shibboleth</a>" SPNameQualifier="<a href="http://everettcc.instructure.com/saml2">http://everettcc.instructure.com/saml2</a>">123456789</saml2:NameID></i></b></div><div><b><i> <saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"></i></b></div><div><b><i> <saml2:SubjectConfirmationData Address="127.0.0.1"</i></b></div><div><b><i> InResponseTo="_cfe9f306-42d4-4e09-8e29-f92fd5d644e6"</i></b></div><div><b><i> NotOnOrAfter="2019-05-20T21:39:57.725Z" Recipient="<a href="https://everettcc.test.instructure.com/login/saml">https://everettcc.test.instructure.com/login/saml</a>"/></i></b></div><div><b><i> </saml2:SubjectConfirmation></i></b></div><div> </saml2:Subject></div><div> <saml2:Conditions NotBefore="2019-05-20T21:34:57.637Z" NotOnOrAfter="2019-05-20T21:39:57.637Z"></div><div> <saml2:AudienceRestriction></div><div> <saml2:Audience><a href="http://everettcc.instructure.com/saml2">http://everettcc.instructure.com/saml2</a></saml2:Audience></div><div> </saml2:AudienceRestriction></div><div> </saml2:Conditions></div><div> <saml2:AuthnStatement AuthnInstant="2019-05-20T21:34:57.437Z" SessionIndex="_0f9fac55868abf7259d74090b72c478f"></div><div> <saml2:SubjectLocality Address="127.0.0.1"/></div><div> <saml2:AuthnContext></div><div> <saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml2:AuthnContextClassRef></div><div> </saml2:AuthnContext></div><div> </saml2:AuthnStatement></div><div> <saml2:AttributeStatement></div><div> <saml2:Attribute FriendlyName="sid"</div><div> Name="urn:oid:0.9.2342.19200300.100.1.1" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"></div><div> <saml2:AttributeValue>123456789</saml2:AttributeValue></div><div> </saml2:Attribute></div><div> </saml2:AttributeStatement></div><div> </saml2:Assertion></div></div><div><br></div><div><br><div>~Jeremy</div><div><br></div></div></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Mon, May 20, 2019 at 2:25 PM Aterea Brown <<a href="mailto:atbrown@aut.ac.nz">atbrown@aut.ac.nz</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<div dir="ltr">
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
Are you using SSO tracer or some other saml capture plugin in your browser? You can check the nameid that has been generated. I think you can also increase the logging for </div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<span> <variable name="idp.loglevel.messages" value="DEBUG" /><br>
</span>
<div> <variable name="idp.loglevel.encryption" value="DEBUG" /><br>
</div>
<span> to see the SAML messages in your log file.</span><br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<span><br>
</span></div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<span>Also bear in mind from <a href="https://wiki.shibboleth.net/confluence/display/IDP30/NameIDGenerationConfiguration" target="_blank">https://wiki.shibboleth.net/confluence/display/IDP30/NameIDGenerationConfiguration</a></span></div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<h3 style="margin:30px 0px 0px;font-weight:bold;line-height:1.5;letter-spacing:-0.006em;font-family:-apple-system,BlinkMacSystemFont,"Segoe UI",Roboto,Oxygen,Ubuntu,"Fira Sans","Droid Sans","Helvetica Neue",sans-serif;background-color:rgb(255,255,255)">
Format Selection</h3>
<p style="margin:10px 0px 0px;color:rgb(23,43,77);font-family:-apple-system,BlinkMacSystemFont,"Segoe UI",Roboto,Oxygen,Ubuntu,"Fira Sans","Droid Sans","Helvetica Neue",sans-serif;font-size:14px;background-color:rgb(255,255,255)">
For any given request, the ordered list of Formats to try to generate is based on combining the SP's request (SAML 2 requests can include a<span> </span><code style="font-family:SFMono-Medium,"SF Mono","Segoe UI Mono","Roboto Mono","Ubuntu Mono",Menlo,Courier,monospace"><NameIDPolicy></code><span> </span>element
that requires a particular Format), the <code style="font-family:SFMono-Medium,"SF Mono","Segoe UI Mono","Roboto Mono","Ubuntu Mono",Menlo,Courier,monospace"><NameIDFormat></code><span> </span>element(s) in the SP's metadata, and the <code style="font-family:SFMono-Medium,"SF Mono","Segoe UI Mono","Roboto Mono","Ubuntu Mono",Menlo,Courier,monospace">nameIDFormatPrecedence</code> <a href="https://wiki.shibboleth.net/confluence/display/IDP30/RelyingPartyConfiguration" style="color:rgb(50,96,186)" target="_blank">profile
configuration</a><span> </span>property, if set for the chosen relying party configuration. If the metadata contains nothing, or contains the "<code style="font-family:SFMono-Medium,"SF Mono","Segoe UI Mono","Roboto Mono","Ubuntu Mono",Menlo,Courier,monospace">urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified</code>"
value, then the metadata is ignored.</p>
<p style="margin:10px 0px 0px;color:rgb(23,43,77);font-family:-apple-system,BlinkMacSystemFont,"Segoe UI",Roboto,Oxygen,Ubuntu,"Fira Sans","Droid Sans","Helvetica Neue",sans-serif;font-size:14px;background-color:rgb(255,255,255)">
If a <code style="font-family:SFMono-Medium,"SF Mono","Segoe UI Mono","Roboto Mono","Ubuntu Mono",Menlo,Courier,monospace"><NameIDPolicy></code><span> </span>element with Format is supplied, a suitable identifier MUST be generated or an error will be
returned.</p>
<p style="margin:10px 0px 0px;color:rgb(23,43,77);font-family:-apple-system,BlinkMacSystemFont,"Segoe UI",Roboto,Oxygen,Ubuntu,"Fira Sans","Droid Sans","Helvetica Neue",sans-serif;font-size:14px;background-color:rgb(255,255,255)">
Otherwise the formats specified in an SP's metadata are filtered against a<span> </span><code style="font-family:SFMono-Medium,"SF Mono","Segoe UI Mono","Roboto Mono","Ubuntu Mono",Menlo,Courier,monospace">nameIDFormatPrecedence</code> <a href="https://wiki.shibboleth.net/confluence/display/IDP30/RelyingPartyConfiguration" style="color:rgb(50,96,186)" target="_blank">profile
configuration</a><span> </span>property, if set, and the resulting set of Formats is tried in order. That is, the first Format in the profile configuration that is also in the metadata and that results in a valid result will be used.</p>
<p style="margin:10px 0px 0px;color:rgb(23,43,77);font-family:-apple-system,BlinkMacSystemFont,"Segoe UI",Roboto,Oxygen,Ubuntu,"Fira Sans","Droid Sans","Helvetica Neue",sans-serif;font-size:14px;background-color:rgb(255,255,255)">
Default Formats for each SAML version are set via<span> </span><em>saml-nameid.properties</em><span> </span>and are used in the event that nothing else is called for. You should<span> </span><strong>not</strong><span> </span>alter that setting in most cases.</p>
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
So you should check whats being returned for nameid. It might not be what you expect.</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<br>
</div>
<div id="gmail-m_8349065667529026374Signature">
<div id="gmail-m_8349065667529026374divtagdefaultwrapper" dir="ltr" style="font-size:12pt;color:rgb(0,0,0);font-family:Calibri,Helvetica,sans-serif">
<div style="font-family:Tahoma;font-size:13px"><font size="2"><font face="Courier New">-art<br>
<br>
</font></font></div>
</div>
<div>
<div id="gmail-m_8349065667529026374appendonsend"></div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<br>
</div>
<hr style="display:inline-block;width:98%">
<div id="gmail-m_8349065667529026374divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" color="#000000" style="font-size:11pt"><b>From:</b> users <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a>> on behalf of Jeremiah Brock <<a href="mailto:jbrock@everettcc.edu" target="_blank">jbrock@everettcc.edu</a>><br>
<b>Sent:</b> Tuesday, 21 May 2019 8:18 AM<br>
<b>To:</b> <a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a><br>
<b>Subject:</b> Canvas Integration Examples</font>
<div> </div>
</div>
<div>
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">Good afternoon,
<div><br>
</div>
<div> I am trying to setup the Canvas SAML authentication using our Shibboleth v3 IDP instance and am having a heck of a time finding any recent documentation.</div>
<div><br>
</div>
<div> I believe that Canvas ONLY supports the NameID or eduPersonPrincipalName for the Login Attribute. So I am attempting to use the NameID that I source on the fly from our sid attribute in the saml-nameid.xml .</div>
<div><br>
</div>
<div> With the current configs (which I will have available below) I am directed to our IDP from Canvas to authenticate and after successful authentication, I am redirected to canvas and receive an error message "There was a problem logging into Everett
Community College".</div>
<div><br>
</div>
<div><br>
</div>
<div><b> metadata-providers.xml</b></div>
<div><b><br>
</b></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<blockquote style="margin:0px 0px 0px 40px;border:none;padding:0px">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div>
<div><MetadataProvider id="CanvasMetadata"</div>
<div> xsi:type="FileBackedHTTPMetadataProvider"</div>
<div> backingFile="/opt/shibboleth-idp/metadata/canvas-metadata.xml"</div>
<div> metadataURL="<a href="https://everettcc.instructure.com/saml2" target="_blank">https://everettcc.instructure.com/saml2</a>"/></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</blockquote>
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div><br>
</div>
<div><br>
</div>
<div><b> attribute-resolver.xml</b></div>
<div><br>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<blockquote style="margin:0px 0px 0px 40px;border:none;padding:0px">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><AttributeDefinition xsi:type="Simple" id="sid" sourceAttributeID="employeenumber"></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div> <Dependency ref="389DSLDAP" /></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div> <AttributeEncoder xsi:type="SAML1String" name="urn:mace:dir:attribute-def:uid" encodeType="false" /></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div> <AttributeEncoder xsi:type="SAML2String" name="urn:oid:0.9.2342.19200300.100.1.1" friendlyName="sid" encodeType="false" /></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div></AttributeDefinition></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</blockquote>
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div><br>
</div>
<div><br>
</div>
</div>
</div>
</div>
</div>
</div>
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div><b> attribute-filter.xml</b></div>
</div>
<blockquote style="margin:0px 0px 0px 40px;border:none;padding:0px">
<div dir="ltr">
<div>
<div><br>
</div>
<div>
<div><!-- For Canvas Testing --></div>
<div> <AttributeFilterPolicy id="InstructureCanvasPolicy"></div>
<div> <PolicyRequirementRule xsi:type="Requester" value="<a href="http://everettcc.instructure.com/saml2" target="_blank">http://everettcc.instructure.com/saml2</a>"/></div>
<div><br>
</div>
<div> <AttributeRule attributeID="NameID"></div>
<div> <PermitValueRule xsi:type="ANY"/></div>
<div> </AttributeRule></div>
<div><br>
</div>
<div> <AttributeRule attributeID="sid"></div>
<div> <PermitValueRule xsi:type="ANY"/></div>
<div> </AttributeRule></div>
<div><br>
</div>
<div> </AttributeFilterPolicy></div>
</div>
</div>
<div><br>
</div>
<div><br>
</div>
</div>
</blockquote>
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div><b> saml-nameid.xml</b></div>
<div><b><br>
</b></div>
</div>
</div>
</div>
</div>
</div>
<blockquote style="margin:0px 0px 0px 40px;border:none;padding:0px">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div>
<div><!-- NEW WAY PER SP!!!! JB 20190520 --></div>
<div><bean parent="shibboleth.SAML2AttributeSourcedGenerator"</div>
<div> p:format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"</div>
<div> p:attributeSourceIds="#{ {'sid'} }"></div>
<div><br>
</div>
<div> <property name="activationCondition"></div>
<div> <bean parent="shibboleth.Conditions.RelyingPartyId"</div>
<div> c:candidate="<a href="http://everettcc.instructure.com/saml2" target="_blank">http://everettcc.instructure.com/saml2</a>" /></div>
<div> </property></div>
<div></bean></div>
<div style="font-weight:bold"><br>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</blockquote>
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div><br>
</div>
<div> <b>relying-party.xml</b></div>
<div><b><br>
</b></div>
</div>
</div>
<blockquote style="margin:0px 0px 0px 40px;border:none;padding:0px">
<div dir="ltr">
<div dir="ltr">
<div>
<div><!-- Canvas--></div>
<div><bean parent="RelyingPartyByName" c:relyingPartyIds="<a href="http://everettcc.instructure.com/saml2" target="_blank">http://everettcc.instructure.com/saml2</a>"></div>
<div> <property name="profileConfigurations"></div>
<div><span style="white-space:pre-wrap"></span> <list></div>
<div><span style="white-space:pre-wrap"></span> <bean parent="Shibboleth.SSO" /></div>
<div><span style="white-space:pre-wrap"></span> <bean parent="SAML2.SSO" </div>
<div><span style="white-space:pre-wrap"></span>p:encryptAssertions="false"</div>
<div><span style="white-space:pre-wrap"></span>p:signAssertions="false"</div>
<div><span style="white-space:pre-wrap"></span>p:encryptNameIDs="false"</div>
<div><span style="white-space:pre-wrap"></span>p:nameIDFormatPrecedence="#{{'urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified'}}" /></div>
<div><span style="white-space:pre-wrap"></span><ref bean="SAML2.Logout" /></div>
<div><span style="white-space:pre-wrap"></span></list></div>
<div> </property></div>
<div></bean></div>
</div>
</div>
</div>
</blockquote>
<div dir="ltr">
<div dir="ltr"><br class="gmail-m_8349065667529026374x_gmail-Apple-interchange-newline">
</div>
</div>
</div>
</div>
</div>
<blockquote style="margin:0px 0px 0px 40px;border:none;padding:0px">
<div dir="ltr">
<div><br>
</div>
</div>
</blockquote>
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div> Here is what I see in the <b>idp-process.log</b> after a successful authentication, the population of NameID with the sid attribute and the release of the sid (but not the NameID?).</div>
<div><br>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<blockquote style="margin:0px 0px 0px 40px;border:none;padding:0px">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div>
<div>2019-05-20 12:57:07,018 - DEBUG [net.shibboleth.idp.saml.attribute.encoding.AbstractSAMLAttributeEncoder:154] - Beginning to encode attribute sid</div>
<div>2019-05-20 12:57:07,018 - DEBUG [net.shibboleth.idp.saml.attribute.encoding.SAMLEncoderSupport:73] - Encoding value 123456789 of attribute sid</div>
<div>2019-05-20 12:57:07,019 - DEBUG [net.shibboleth.idp.saml.attribute.encoding.AbstractSAMLAttributeEncoder:191] - Completed encoding 1 values for attribute sid</div>
<div>2019-05-20 12:57:07,019 - DEBUG [net.shibboleth.idp.saml.saml2.profile.impl.AddAttributeStatementToAssertion:116] - Profile Action AddAttributeStatementToAssertion: Adding constructed AttributeStatement to Assertion _2aa1a4c562370d0af02cbf0adce804ac </div>
<div>2019-05-20 12:57:07,023 - DEBUG [net.shibboleth.idp.saml.profile.logic.DefaultNameIdentifierFormatStrategy:124] - Configuration specifies the following formats: [urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified]</div>
<div>2019-05-20 12:57:07,023 - DEBUG [net.shibboleth.idp.saml.profile.logic.DefaultNameIdentifierFormatStrategy:141] - Metadata did not specify any formats, relying on configuration alone</div>
<div>2019-05-20 12:57:07,024 - DEBUG [net.shibboleth.idp.saml.nameid.impl.AttributeSourcedSAML2NameIDGenerator:197] -
<b>Checking for source attribute sid</b></div>
<div>2019-05-20 12:57:07,024 - DEBUG [net.shibboleth.idp.saml.nameid.impl.AttributeSourcedSAML2NameIDGenerator:216] -
<b>Generating NameID from String-valued attribute sid</b></div>
<div>2019-05-20 12:57:07,041 - DEBUG [net.shibboleth.idp.saml.saml2.profile.delegation.impl.DecorateDelegatedAssertion:592] - Found Assertion with AuthnStatement to decorate in outbound Response</div>
<div>2019-05-20 12:57:07,041 - DEBUG [net.shibboleth.idp.saml.saml2.profile.delegation.impl.DecorateDelegatedAssertion:290] - Issuance of delegated was not indicated, skipping assertion decoration</div>
<div>2019-05-20 12:57:07,062 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:179] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler of type 'org.opensaml.messaging.handler.impl.BasicMessageHandlerChain' on OUTBOUND
message context</div>
<div>2019-05-20 12:57:07,062 - DEBUG [net.shibboleth.idp.profile.impl.WebFlowMessageHandlerAdaptor:195] - Profile Action WebFlowMessageHandlerAdaptor: Invoking message handler on message context containing a message of type 'org.opensaml.saml.saml2.core.impl.ResponseImpl'</div>
<div>2019-05-20 12:57:07,068 - DEBUG [net.shibboleth.idp.saml.profile.impl.SpringAwareMessageEncoderFactory:100] - Looking up message encoder based on binding URI: urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST</div>
<div>2019-05-20 12:57:07,072 - DEBUG [net.shibboleth.idp.profile.impl.RecordResponseComplete:89] - Profile Action RecordResponseComplete: Record response complete</div>
<div>2019-05-20 12:57:07,073 - INFO [Shibboleth-Audit.SSO:275] - 20190520T195707Z|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect|_bd08fcee-9195-4093-b01d-428224c54864|<a href="http://everettcc.instructure.com/saml2%7Chttp://shibboleth.net/ns/profiles/saml2/sso/browser%7Chttps://idp-389ds-test.everettcc.edu/idp/shibboleth%7Curn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST%7C_2dfbb1143bb975720f03d1582c5960c7%7Cjbrock%7Curn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport%7Csid%7C123456789%7C_2aa1a4c562370d0af02cbf0adce804ac%7C" target="_blank">http://everettcc.instructure.com/saml2|http://shibboleth.net/ns/profiles/saml2/sso/browser|https://idp-389ds-test.everettcc.edu/idp/shibboleth|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST|_2dfbb1143bb975720f03d1582c5960c7|jbrock|urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport|sid|123456789|_2aa1a4c562370d0af02cbf0adce804ac|</a></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</blockquote>
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div><br>
</div>
<div><br>
</div>
<div> In the Canvas SAML options I have the following :</div>
<div><br>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<blockquote style="margin:0px 0px 0px 40px;border:none;padding:0px">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div>Login Attribute : NameID</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</blockquote>
<blockquote style="margin:0px 0px 0px 40px;border:none;padding:0px">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div>Identifier Format : urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</blockquote>
<blockquote style="margin:0px 0px 0px 40px;border:none;padding:0px">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div>Authentication Context : No value</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</blockquote>
<blockquote style="margin:0px 0px 0px 40px;border:none;padding:0px">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div>Message Signing : Not Signed</div>
<div><br>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</blockquote>
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div> Thanks for any advise or working examples.</div>
<div><br>
</div>
<div>~Jeremy</div>
-- <br>
<div dir="ltr" class="gmail-m_8349065667529026374x_gmail_signature">
<div dir="ltr">
<div>
<div dir="ltr">Jeremiah Brock<br>
<span style="font-size:12.8px">IT Web, Data and Development Services / Information Security</span><br>
</div>
<div dir="ltr">425-259-8707<br>
<a href="mailto:jbrock@everettcc.edu" target="_blank">jbrock@everettcc.edu</a></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a></blockquote></div><br clear="all"><div><br></div>-- <br><div dir="ltr" class="gmail_signature"><div dir="ltr"><div><div dir="ltr">Jeremiah Brock<br><span style="font-size:12.8px">IT Web, Data and Development Services / Information Security</span><br></div><div dir="ltr">425-259-8707<br><a href="mailto:jbrock@everettcc.edu" target="_blank">jbrock@everettcc.edu</a></div></div></div></div>