<div dir="ltr">Your resolver defines the attribute as a NameID:<br><span style="color:rgb(0,0,0);font-family:arial,sans-serif;font-variant-ligatures:no-common-ligatures"><</span><span style="color:rgb(0,0,0);font-family:arial,sans-serif;font-variant-ligatures:no-common-ligatures">resolver</span><span style="color:rgb(0,0,0);font-family:arial,sans-serif;font-variant-ligatures:no-common-ligatures">:</span><span style="color:rgb(0,0,0);font-family:arial,sans-serif;font-variant-ligatures:no-common-ligatures">AttributeEncoder </span><span style="color:rgb(0,0,0);font-family:arial,sans-serif;font-variant-ligatures:no-common-ligatures">xsi</span><span style="color:rgb(0,0,0);font-family:arial,sans-serif;font-variant-ligatures:no-common-ligatures">:</span><span style="color:rgb(0,0,0);font-family:arial,sans-serif;font-variant-ligatures:no-common-ligatures">type</span><span style="color:rgb(0,0,0);font-family:arial,sans-serif;font-variant-ligatures:no-common-ligatures">=</span><span style="color:rgb(0,0,0);font-family:arial,sans-serif;font-variant-ligatures:no-common-ligatures">"SAML2StringNameID"</span><br><div><span style="color:rgb(0,0,0);font-family:arial,sans-serif;font-variant-ligatures:no-common-ligatures">and as Mak pointed out, that is what is released:</span><br style="color:rgb(80,0,80);font-family:Helvetica"><span style="color:rgb(80,0,80);font-family:Helvetica"><saml2:NameID...></span><span style="color:rgb(80,0,80);font-family:Helvetica">trename01</span><span style="color:rgb(80,0,80);font-family:Helvetica"></saml2:NameID></span><span style="color:rgb(0,0,0);font-family:arial,sans-serif;font-variant-ligatures:no-common-ligatures"><br></span></div><div><span style="color:rgb(80,0,80);font-family:Helvetica"><br></span></div><div><span style="color:rgb(80,0,80);font-family:Helvetica">Both the resolver and the SAML assertion have the "persistent" format as well.</span></div><div><span style="color:rgb(80,0,80);font-family:Helvetica"><br></span></div><div><span style="color:rgb(80,0,80);font-family:Helvetica">The name </span><span style="color:rgb(0,0,0);font-family:arial,sans-serif;font-variant-ligatures:no-common-ligatures">"</span><span style="color:rgb(0,0,0);font-family:arial,sans-serif;font-variant-ligatures:no-common-ligatures">Beyond</span><span style="color:rgb(0,0,0);font-family:arial,sans-serif;font-variant-ligatures:no-common-ligatures">TrustUsername" is a convenience for your internal use,</span></div><div><span style="color:rgb(0,0,0);font-family:arial,sans-serif;font-variant-ligatures:no-common-ligatures">it is not the SAML name of the attribute.</span></div><div><span style="color:rgb(0,0,0);font-family:arial,sans-serif;font-variant-ligatures:no-common-ligatures"><br></span></div><div><span style="color:rgb(80,0,80);font-family:Helvetica">I don't know what Beyond Trust is specifically looking for if not a SAML NameID <br>with the right format. I've encountered vendors looking at the "friendlyName"</span></div><div><span style="color:rgb(80,0,80);font-family:Helvetica">instead of the name of the attribute. If that's so in your case, you might</span></div><div><span style="color:rgb(80,0,80);font-family:Helvetica">add a "friendlyName" to the SAML attribute definition encoder statement.</span></div><div><span style="color:rgb(80,0,80);font-family:Helvetica"><br></span></div><div><span style="color:rgb(80,0,80);font-family:Helvetica">David Bantz</span></div><div><span style="color:rgb(80,0,80);font-family:Helvetica">UA OIT IAM</span></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Wed, Apr 8, 2020 at 8:44 AM Mathis, Bradley <<a href="mailto:bmathis@pima.edu">bmathis@pima.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr">Hi Steve, Ah I see what you mean.. the subject of my email I realize wasn't a good description. This is probably due to my lack of understanding.... I guess what I'm expecting to see is the Attribute "BeyondTrustUsername" being released .... as that is what the SP is trying to MAP to username. As you can see in the SAML trace "uid" is being released if I try to have the SP map their username to "uid"... it doesn't recognize it .. I was thinking it didn't recognize "uid" since it wasn't a persistent nameid attribute .....which is why I created the "BeyondTrustUsername" attribute. .. which does not appear to be released.<div><br></div><div>Thanks for your input and patience with my explanations. I'm fairly certain I'm confusing some with my incorrect use of terminology and making inaccurate assumptions. I must be misunderstanding how the NameId format and release of attributes actually work. Any other input is appreciated.</div><div><br clear="all"><div><div dir="ltr"><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div><div></div><div><br></div><div>Brad Mathis</div><div>IT Systems Architect </div><div>Infrastructure Services - Applications<br></div><div>Pima Community College<br></div><div>520.206.4826<br></div><div><a href="mailto:bmathis@pima.edu" target="_blank">bmathis@pima.edu</a></div></div><div><br></div><div><img src="https://drive.google.com/a/pima.edu/uc?id=1-cXzKNARwUoDuBUcqPuKHQtqN6T9Kc-K&export=download" width="200" height="147"><br></div><div><br></div><div><br></div><div><br></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div><br></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Wed, Apr 8, 2020 at 8:57 AM Mak, Steve <<a href="mailto:makst@upenn.edu" target="_blank">makst@upenn.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<div lang="EN-US">
<div>
<p class="MsoNormal"><span style="font-family:Helvetica">It's right here:<br>
<br>
<saml2:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:persistent" NameQualifier="<a href="https://idp.pima.edu/idp/shibboleth" target="_blank">https://idp.pima.edu/idp/shibboleth</a>" SPNameQualifier="<a href="https://pima.beyondtrustcloud.com" target="_blank">https://pima.beyondtrustcloud.com</a>">trename01</saml2:NameID><u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-family:Helvetica"><u></u> <u></u></span></p>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a></blockquote></div>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a></blockquote></div>