<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
</head>
<body text="#000000" bgcolor="#FFFFFF">
<p>Okay, to answer my own question, I had to change the SSO into:</p>
<p><SSO discoveryProtocol="SAMLDS" discoveryURL=<a
class="moz-txt-link-rfc2396E"
href="https://wayf.aai.dfn.de/DFN-AAI-Test/wayf/www/WAYF.php">"https://wayf.aai.dfn.de/DFN-AAI-Test/wayf"</a>>SAML2</SSO></p>
<p>Now it uses SAML2 and I get an persistentId.</p>
<p>Stefan<br>
</p>
<div class="moz-cite-prefix">Am 21.11.2019 um 08:24 schrieb Stefan
Kombrink:<br>
</div>
<blockquote type="cite"
cite="mid:85289e12-7548-1e78-acf4-047af0a175a5@uni-ulm.de">
<meta http-equiv="content-type" content="text/html; charset=UTF-8">
<p>Dear community,</p>
<p> I've got a SP setup, where I require the persistentId, and I
want to attach a discovery service. <br>
</p>
<p>As long as I define a single IdP as entityId I retrieve the
persistentId during a session:</p>
<p><SSO entityID=<a class="moz-txt-link-rfc2396E"
href="https://idp-test.rz.uni-ulm.de/idp/shibboleth"
moz-do-not-send="true">"https://idp-test.rz.uni-ulm.de/idp/shibboleth"</a>>SAML2
SAML1</SSO></p>
<pre><strong>SSO Protocol:</strong> urn:oasis:names:tc:SAML:2.0:protocol
<strong>Authentication Context Class:</strong> urn:oasis:names:tc:SAML:2.0:ac:<a class="moz-txt-link-freetext" href="classes:PasswordProtectedTransport" moz-do-not-send="true">classes:PasswordProtectedTransport</a></pre>
<p>When I switch over to WAYF:</p>
<p><SSO discoveryProtocol="WAYF" ECP="true"
discoveryURL=<a class="moz-txt-link-rfc2396E"
href="https://wayf.aai.dfn.de/DFN-AAI-Test/wayf/www/WAYF.php"
moz-do-not-send="true">"https://wayf.aai.dfn.de/DFN-AAI-Test/wayf/www/WAYF.php"</a>>SAML2
SAML1</SSO></p>
<p>I do not get the persistentId any longer. Furthermore, I can
see the Session is using</p>
<pre><strong>SSO Protocol:</strong> urn:oasis:names:tc:SAML:1.1:protocol
<strong>Authentication Context Class:</strong> urn:oasis:names:tc:SAML:1.0:am:password
</pre>
<p>To me it seems as if the WAYF forces it to use SAML1, and
that's why I do not obtain the entityID. Is that so?</p>
<p>Is there a discovery service I could use instead which will be
SAML2 compatible and give me the persistentID?</p>
<p><br>
</p>
<p>thanks & best regards<br>
</p>
<p>Stefan<br>
</p>
<pre class="moz-signature" cols="72">--
Kontaktdaten: <a class="moz-txt-link-freetext" href="https://portal.uni-ulm.de/ETB/ab/showPerson.html?pid=46110" moz-do-not-send="true">https://portal.uni-ulm.de/ETB/ab/showPerson.html?pid=46110</a></pre>
<br>
<fieldset class="mimeAttachmentHeader"></fieldset>
</blockquote>
<pre class="moz-signature" cols="72">--
Kontaktdaten: <a class="moz-txt-link-freetext" href="https://portal.uni-ulm.de/ETB/ab/showPerson.html?pid=46110">https://portal.uni-ulm.de/ETB/ab/showPerson.html?pid=46110</a></pre>
</body>
</html>