<div dir="ltr">Thank you for your response Aterea, I forgot to mention (and I meant to) .. I'm using idp 2.x ... at least in production. I do have idp 3.x setup in test and can see the file you are referring to .. and it appears I actually have used that file to help setup SSO for gmail at one point. Thanks again.<div><br></div><div>Still looking for any feedback on why things are happening the way they are in my idp 2.x environment.. if anyone has an idea ..</div><div><br></div><div>Thanks!<br clear="all"><div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div><div></div><div><br></div><div>Brad Mathis</div><div>IT Systems Architect (Acting)</div><div>Infrastructure Services - Applications<br></div><div>Pima Community College<br></div><div>520.206.4826<br></div><div><a href="mailto:bmathis@pima.edu" target="_blank">bmathis@pima.edu</a></div></div><div><br></div><div><img src="https://docs.google.com/uc?export=download&id=1kpePdW3WkXNvx95EBuHo26kg1x50E5s4&revid=0B4QEFWYNTFJAcnoxVkhJaGtHaHBqdEI2SENTN0J1ODJmUkg0PQ" width="200" height="127"><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div><br></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Wed, Nov 13, 2019 at 12:29 PM Aterea Brown <<a href="mailto:atbrown@aut.ac.nz">atbrown@aut.ac.nz</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<div dir="ltr">
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
Hi Mathis,</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
Typically I use the file saml-nameid.xml to set the persistent id generator to use the specified format.</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
you then only need to release the actual attribute to the sp. So in this cause you would have a clause in attribute-filter.xml that releases eMailAddress.</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
Then in the saml-nameid.xml you could have 2 entries for the sp.</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
you wil lneed an entry that will tell the generator not to use the default method.</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
then an entry that says for entityid blah use method xyz.</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
should be examples in that file.</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif;font-size:12pt;color:rgb(0,0,0)">
<br>
</div>
<div id="gmail-m_1957279487355630156Signature">
<div id="gmail-m_1957279487355630156divtagdefaultwrapper" dir="ltr" style="font-size:12pt;color:rgb(0,0,0);font-family:Calibri,Helvetica,sans-serif">
<div style="font-family:Tahoma;font-size:13px"><font size="2"><font face="Courier New">--<br>
Aterea Brown, AUT University<br>
Cybersecurity, ICT<br>
Email: <a href="mailto:atbrown@aut.ac.nz" target="_blank">atbrown@aut.ac.nz</a> Phone: 9219999 x 6523</font></font></div>
</div>
</div>
<div id="gmail-m_1957279487355630156appendonsend"></div>
<hr style="display:inline-block;width:98%">
<div id="gmail-m_1957279487355630156divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> users <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a>> on behalf of Mathis, Bradley <<a href="mailto:bmathis@pima.edu" target="_blank">bmathis@pima.edu</a>><br>
<b>Sent:</b> Thursday, 14 November 2019 8:05 AM<br>
<b>To:</b> Shib Users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
<b>Cc:</b> White, Jeff <<a href="mailto:jwhite@pima.edu" target="_blank">jwhite@pima.edu</a>><br>
<b>Subject:</b> Subject NameID format question</font>
<div> </div>
</div>
<div>
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div><br>
</div>
<div>I have set setup SSO for couple of applications where the SP requires Subject NameID format to be Format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress"</div>
<div><br>
</div>
<div>I'm able to do this successfully only if I release a specific attribute that's defined in my attribute-resolver.xml as "user_id" e.g.</div>
<div><br>
</div>
<div>
<div> <resolver:AttributeDefinition xsi:type="ad:Template" id="user_id"></div>
<div> <resolver:Dependency ref="myLDAP" /></div>
<div> <resolver:AttributeEncoder xsi:type="enc:SAML2StringNameID" nameFormat="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress" /></div>
<div> <ad:SourceAttribute>mail</ad:SourceAttribute></div>
<div></resolver:AttributeDefinition></div>
</div>
<div><br>
</div>
<div><br>
</div>
<div>The part I don't understand is this I have at least 2 other attributes definitions in the attribute-resolver.xml that do not work if I release them instead, such as the attribute "frshid"</div>
<div><br>
</div>
<div>
<div><resolver:AttributeDefinition xsi:type="ad:Template" id="frshid"></div>
<div> <resolver:Dependency ref="myLDAP" /></div>
<div> <resolver:AttributeEncoder xsi:type="enc:SAML2StringNameID" nameFormat="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress" /></div>
<div> <ad:SourceAttribute>mail</ad:SourceAttribute></div>
<div></resolver:AttributeDefinition></div>
</div>
<div><br>
</div>
<div><br>
</div>
<div>Here a snippet of the Subject from a SAML trace when it works releasing the attribute "user_id"</div>
<div><br>
</div>
<div>
<div><span style="white-space:pre-wrap"></span><saml2:Subject></div>
<div><span style="white-space:pre-wrap"></span><saml2:NameID Format="<span style="background-color:rgb(255,255,0)">urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress</span>"</div>
<div><span style="white-space:pre-wrap"></span> NameQualifier="<a href="https://idp.pima.edu/idp/shibboleth" target="_blank">https://idp.pima.edu/idp/shibboleth</a>"</div>
<div><span style="white-space:pre-wrap"></span> SPNameQualifier="<a href="https://www.okta.com/saml2/service-provider/spin7qorz7IoNah7c0x7" target="_blank">https://www.okta.com/saml2/service-provider/spin7qorz7IoNah7c0x7</a>"</div>
<div><span style="white-space:pre-wrap"></span> ><span style="background-color:rgb(255,255,0)"><a href="mailto:trename01@pima.edu" target="_blank">trename01@pima.edu</a></span></saml2:NameID></div>
<div><span style="white-space:pre-wrap"></span><saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"></div>
<div><span style="white-space:pre-wrap"></span><saml2:SubjectConfirmationData Address="144.90.132.76"</div>
<div><span style="white-space:pre-wrap"></span> InResponseTo="id191289947414822031926171130"</div>
<div><span style="white-space:pre-wrap"></span> NotOnOrAfter="2019-11-05T16:09:32.123Z"</div>
<div><span style="white-space:pre-wrap"></span> Recipient="<a href="https://adbe-4bf37e265d9f449a0a495ce8-cdcd-prd.okta.com/auth/saml20/accauthlinktest" target="_blank">https://adbe-4bf37e265d9f449a0a495ce8-cdcd-prd.okta.com/auth/saml20/accauthlinktest</a>"</div>
<div><span style="white-space:pre-wrap"></span> /></div>
<div><span style="white-space:pre-wrap"></span></saml2:SubjectConfirmation></div>
</div>
<div><br>
</div>
<div><br>
</div>
<div>Here's a snippet of the Subject from a SAML trace when it doesn't work releasing the attribute "frshid".</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div>
<div><saml2:Subject></div>
<div><span style="white-space:pre-wrap"></span><saml2:NameID Format="<span style="background-color:rgb(255,255,0)">urn:oasis:names:tc:SAML:2.0:nameid-format:transient</span>"</div>
<div><span style="white-space:pre-wrap"></span> NameQualifier="<a href="https://idp.pima.edu/idp/shibboleth" target="_blank">https://idp.pima.edu/idp/shibboleth</a>"</div>
<div><span style="white-space:pre-wrap"></span> SPNameQualifier="<a href="https://www.okta.com/saml2/service-provider/spin7qorz7IoNah7c0x7" target="_blank">https://www.okta.com/saml2/service-provider/spin7qorz7IoNah7c0x7</a>"</div>
<div><span style="white-space:pre-wrap"></span> ><span style="background-color:rgb(255,255,0)">_fedcaab0bd32f85998a32e26b7ed8e73</span></saml2:NameID></div>
<div><span style="white-space:pre-wrap"></span><saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"></div>
<div><span style="white-space:pre-wrap"></span><saml2:SubjectConfirmationData Address="144.90.132.76"</div>
<div><span style="white-space:pre-wrap"></span> InResponseTo="id191277203610250932120081916"</div>
<div><span style="white-space:pre-wrap"></span> NotOnOrAfter="2019-11-05T15:48:05.448Z"</div>
<div><span style="white-space:pre-wrap"></span> Recipient="<a href="https://adbe-4bf37e265d9f449a0a495ce8-cdcd-prd.okta.com/auth/saml20/accauthlinktest" target="_blank">https://adbe-4bf37e265d9f449a0a495ce8-cdcd-prd.okta.com/auth/saml20/accauthlinktest</a>"</div>
<div><span style="white-space:pre-wrap"></span> /></div>
<div><span style="white-space:pre-wrap"></span></saml2:SubjectConfirmation></div>
</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div>Why does it only work when I use the attribute "user_id"? I'm glad I was able to make it work but not happy that I don't understand why. I will be happy to answer any questions for further clarification if needed.</div>
<div><br>
</div>
<div>Thanks for any feedback.</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<br clear="all">
<div>
<div dir="ltr">
<div dir="ltr">
<div>
<div dir="ltr">
<div>
<div dir="ltr">
<div>
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div dir="ltr">
<div>
<div></div>
<div><br>
</div>
<div>Brad Mathis</div>
<div>IT Systems Architect (Acting)</div>
<div>Infrastructure Services - Applications<br>
</div>
<div>Pima Community College<br>
</div>
<div>520.206.4826<br>
</div>
<div><a href="mailto:bmathis@pima.edu" target="_blank">bmathis@pima.edu</a></div>
</div>
<div><br>
</div>
<div><img width="200" height="127" src="https://docs.google.com/uc?export=download&id=1kpePdW3WkXNvx95EBuHo26kg1x50E5s4&revid=0B4QEFWYNTFJAcnoxVkhJaGtHaHBqdEI2SENTN0J1ODJmUkg0PQ"><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a></blockquote></div>