<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    <p>Okay, to answer my own question, I had to change the SSO into:</p>
    <p><SSO discoveryProtocol="SAMLDS" discoveryURL=<a
        class="moz-txt-link-rfc2396E"
        href="https://wayf.aai.dfn.de/DFN-AAI-Test/wayf/www/WAYF.php">"https://wayf.aai.dfn.de/DFN-AAI-Test/wayf"</a>>SAML2</SSO></p>
    <p>Now it uses SAML2 and I get an persistentId.</p>
    <p>Stefan<br>
    </p>
    <div class="moz-cite-prefix">Am 21.11.2019 um 08:24 schrieb Stefan
      Kombrink:<br>
    </div>
    <blockquote type="cite"
      cite="mid:85289e12-7548-1e78-acf4-047af0a175a5@uni-ulm.de">
      <meta http-equiv="content-type" content="text/html; charset=UTF-8">
      <p>Dear community,</p>
      <p> I've got a SP setup, where I require the persistentId, and I
        want to attach a discovery service. <br>
      </p>
      <p>As long as I define a single IdP as entityId I retrieve the
        persistentId during a session:</p>
      <p><SSO entityID=<a class="moz-txt-link-rfc2396E"
          href="https://idp-test.rz.uni-ulm.de/idp/shibboleth"
          moz-do-not-send="true">"https://idp-test.rz.uni-ulm.de/idp/shibboleth"</a>>SAML2
        SAML1</SSO></p>
      <pre><strong>SSO Protocol:</strong> urn:oasis:names:tc:SAML:2.0:protocol
<strong>Authentication Context Class:</strong> urn:oasis:names:tc:SAML:2.0:ac:<a class="moz-txt-link-freetext" href="classes:PasswordProtectedTransport" moz-do-not-send="true">classes:PasswordProtectedTransport</a></pre>
      <p>When I switch over to WAYF:</p>
      <p><SSO discoveryProtocol="WAYF" ECP="true"
        discoveryURL=<a class="moz-txt-link-rfc2396E"
          href="https://wayf.aai.dfn.de/DFN-AAI-Test/wayf/www/WAYF.php"
          moz-do-not-send="true">"https://wayf.aai.dfn.de/DFN-AAI-Test/wayf/www/WAYF.php"</a>>SAML2
        SAML1</SSO></p>
      <p>I do not get the persistentId any longer. Furthermore, I can
        see the Session is using</p>
      <pre><strong>SSO Protocol:</strong> urn:oasis:names:tc:SAML:1.1:protocol
<strong>Authentication Context Class:</strong> urn:oasis:names:tc:SAML:1.0:am:password

</pre>
      <p>To me it seems as if the WAYF forces it to use SAML1, and
        that's why I do not obtain the entityID. Is that so?</p>
      <p>Is there a discovery service I could use instead which will be
        SAML2 compatible and give me the persistentID?</p>
      <p><br>
      </p>
      <p>thanks & best regards<br>
      </p>
      <p>Stefan<br>
      </p>
      <pre class="moz-signature" cols="72">-- 
Kontaktdaten: <a class="moz-txt-link-freetext" href="https://portal.uni-ulm.de/ETB/ab/showPerson.html?pid=46110" moz-do-not-send="true">https://portal.uni-ulm.de/ETB/ab/showPerson.html?pid=46110</a></pre>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
    </blockquote>
    <pre class="moz-signature" cols="72">-- 
Kontaktdaten: <a class="moz-txt-link-freetext" href="https://portal.uni-ulm.de/ETB/ab/showPerson.html?pid=46110">https://portal.uni-ulm.de/ETB/ab/showPerson.html?pid=46110</a></pre>
  </body>
</html>