<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
My notes from our integration with EverFi is that they want a persistent id in the format of urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
We added a SAML2NameId Generator to saml-nameid.xml to send them EPPN</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<span>       <bean parent="shibboleth.SAML2AttributeSourcedGenerator"<br>
</span>
<div>             p:omitQualifiers="true"<br>
</div>
<div>             p:format="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"</div>
<div>             p:attributeSourceIds="#{ {'eduPersonPrincipalName'} }"><br>
</div>
<div>         <property name="activationCondition"><br>
</div>
<div>            <bean parent="shibboleth.Conditions.RelyingPartyId"<br>
</div>
<div>                  c:candidates="#{{</div>
<div>                    'https://fifoundry.net/saml/sp'</div>
<div>                  }}"/><br>
</div>
<div>         </property><br>
</div>
<span>       </bean></span><br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<span><br>
</span></div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<span>And then configured the relying-party to force unspecified and disable encryption of NameIDs.</span></div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<span><br>
</span></div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<span><span>      <bean parent="RelyingPartyByName"<br>
</span>
<div>            c:relyingPartyIds="#{{<br>
</div>
<div>                                  'https://fifoundry.net/saml/sp'</div>
<div>                                }}" ><br>
</div>
<div>         <property name="profileConfigurations"><br>
</div>
<div>            <list><br>
</div>
<div>               <bean parent="SAML2.SSO"<br>
</div>
<div>                     p:nameIDFormatPrecedence="urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"<br>
</div>
<div>                     p:signResponses="true"<br>
</div>
<div>                     p:signAssertions="true"<br>
</div>
<div>                     p:encryptAssertions="true"<br>
</div>
<div>                     p:encryptNameIDs="false" /><br>
</div>
<div>               <bean parent="SAML2.ECP"<br>
</div>
<div>                     p:signResponses="true"<br>
</div>
<div>                     p:signAssertions="true"<br>
</div>
<div>                     p:encryptAssertions="true"<br>
</div>
<div>                     p:encryptNameIDs="false" /><br>
</div>
<div>            </list><br>
</div>
<div>         </property><br>
</div>
<span>      </bean></span><br>
</span></div>
<div>
<div id="appendonsend"></div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
-James</div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<hr tabindex="-1" style="display:inline-block; width:98%">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" color="#000000" style="font-size:11pt"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of mhc-shib-admin <cswoods@mtholyoke.edu><br>
<b>Sent:</b> Wednesday, January 8, 2020 9:43 AM<br>
<b>To:</b> users@shibboleth.net <users@shibboleth.net><br>
<b>Subject:</b> eduPersonTargetedID not being sent as persistent</font>
<div> </div>
</div>
<div class="BodyFragment"><font size="2"><span style="font-size:11pt">
<div class="PlainText">[External Email]<br>
<br>
Hi Folks-<br>
<br>
I am setting up our IDP (v3.3) to work with Everfi. They are asking for a<br>
persistent nameID so I am sending them eduPersonTargetedID. On examining the<br>
SAML, I find this:<br>
<br>
<saml2:Subject><br>
            <saml2:NameID<br>
Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient"<br>
                NameQualifier="<a href=""></a>https://urldefense.proofpoint.com/v2/url?u=https-3A__sso.mtholyoke.edu_idp_shibboleth&d=DwICAg&c=sJ6xIWYx-zLMB3EPkvcnVg&r=_L7sACgIQaR0AZonCJxTrg&m=cDucy65-TFMRxFpieoaTxjzjI0PaSXLMUElCQxSXiFs&s=L7ZSO0pmrFS5YjcVKJ-lAV7uNO9bhwaXLvcLF7-znmM&e=
 "<br>
<br>
SPNameQualifier="<a href=""></a>https://urldefense.proofpoint.com/v2/url?u=https-3A__admin.fifoundry.net_mount-5Fholyoke-5Fcollege_saml_sp&d=DwICAg&c=sJ6xIWYx-zLMB3EPkvcnVg&r=_L7sACgIQaR0AZonCJxTrg&m=cDucy65-TFMRxFpieoaTxjzjI0PaSXLMUElCQxSXiFs&s=gJbUKDlwQqznGSaKjRAUJe6Fpkpnz_VbzTW9lFFN-kc&e=
 ">AAdzZWN....</saml2:NameID><br>
</saml2:Subject><br>
<br>
I didn't this was possible but as it, apparently is, can anyone suggest how<br>
I can change it to persistent?<br>
<br>
Thanks very much.<br>
<br>
<br>
<br>
--<br>
Sent from: <a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__shibboleth.1660669.n2.nabble.com_Shibboleth-2DUsers-2Df1660767.html&d=DwICAg&c=sJ6xIWYx-zLMB3EPkvcnVg&r=_L7sACgIQaR0AZonCJxTrg&m=cDucy65-TFMRxFpieoaTxjzjI0PaSXLMUElCQxSXiFs&s=arHFi2oZD-wi9y6RYRLHx9rImGhNlT1prglqq0t2RGE&e=">
https://urldefense.proofpoint.com/v2/url?u=https-3A__shibboleth.1660669.n2.nabble.com_Shibboleth-2DUsers-2Df1660767.html&d=DwICAg&c=sJ6xIWYx-zLMB3EPkvcnVg&r=_L7sACgIQaR0AZonCJxTrg&m=cDucy65-TFMRxFpieoaTxjzjI0PaSXLMUElCQxSXiFs&s=arHFi2oZD-wi9y6RYRLHx9rImGhNlT1prglqq0t2RGE&e=</a><br>
--<br>
For Consortium Member technical support, see <a href="https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.shibboleth.net_confluence_x_coFAAg&d=DwICAg&c=sJ6xIWYx-zLMB3EPkvcnVg&r=_L7sACgIQaR0AZonCJxTrg&m=cDucy65-TFMRxFpieoaTxjzjI0PaSXLMUElCQxSXiFs&s=cDJS6M5Z1rWcRQMTYBJZvJMFSOB7BH8q-kG9xoS1oeA&e=">
https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.shibboleth.net_confluence_x_coFAAg&d=DwICAg&c=sJ6xIWYx-zLMB3EPkvcnVg&r=_L7sACgIQaR0AZonCJxTrg&m=cDucy65-TFMRxFpieoaTxjzjI0PaSXLMUElCQxSXiFs&s=cDJS6M5Z1rWcRQMTYBJZvJMFSOB7BH8q-kG9xoS1oeA&e=</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font></div>
</div>
</body>
</html>