<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 9pt; color: rgb(0, 0, 0);">
Scott,</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 9pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 9pt; color: rgb(0, 0, 0);">
We're being informed now, that NameID is the only way supported to send in a user matching value.
<br>
</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 9pt; color: rgb(0, 0, 0);">
Is it possible for you to confirm if that integration was in fact with an attribute (or a custom attribute) or just setting the NameID to an email or user id to match in their data?</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 9pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 9pt; color: rgb(0, 0, 0);">
I don't know if the product versions on their end have anything to do with their SSO model.
<br>
</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 9pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 9pt; color: rgb(0, 0, 0);">
Their documentation shared with us says this for SAML 2.0 integration:</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 9pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 9pt; color: rgb(0, 0, 0);">
<span style="left: 92.192px; top: 313.533px; font-size: 13.44px; font-family: sans-serif; transform: scaleX(0.912283)"><b>Element</b>: NameID</span><span style="left: 243.933px; top: 241.213px; font-size: 13.44px; font-family: sans-serif; transform: scaleX(0.91707)"><br>
</span></div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 9pt; color: rgb(0, 0, 0);">
<span style="left: 243.933px; top: 241.213px; font-size: 13.44px; font-family: sans-serif; transform: scaleX(0.91707)"><br>
</span></div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 9pt; color: rgb(0, 0, 0);">
<span style="left: 243.933px; top: 241.213px; font-size: 13.44px; font-family: sans-serif; transform: scaleX(0.91707)"><b>Definition</b>: This element contains the User's identifier
</span><span style="left: 243.933px; top: 260.093px; font-size: 13.44px; font-family: sans-serif; transform: scaleX(0.955284)">information to log</span><span style="left: 342.5333333333333px; top: 260.0933333333334px; font-size: 13.44px; font-family: sans-serif">-</span><span style="left: 346.373px; top: 260.093px; font-size: 13.44px; font-family: sans-serif; transform: scaleX(0.869458)">in
to CSOD. This could be </span><span style="left: 243.933px; top: 278.653px; font-size: 13.44px; font-family: sans-serif; transform: scaleX(0.898546)">an</span><span style="left: 257.373px; top: 278.653px; font-size: 13.44px; font-family: sans-serif; transform: scaleX(0.924341)">y
of the following <br>
</span></div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 9pt; color: rgb(0, 0, 0);">
<span style="left: 257.373px; top: 278.653px; font-size: 13.44px; font-family: sans-serif; transform: scaleX(0.924341)">User fields:</span><span style="left: 255.133px; top: 310.653px; font-size: 13.44px; font-family: sans-serif; transform: scaleX(0.917507)"><br>
</span></div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 9pt; color: rgb(0, 0, 0);">
<ul>
<li><span style="left: 255.133px; top: 310.653px; font-size: 13.44px; font-family: sans-serif; transform: scaleX(0.917507)">User ID</span><span style="left: 255.133px; top: 329.533px; font-size: 13.44px; font-family: sans-serif; transform: scaleX(0.931505)"></span></li><li><span style="left: 255.133px; top: 329.533px; font-size: 13.44px; font-family: sans-serif; transform: scaleX(0.931505)">Username</span><span style="left: 255.133px; top: 348.133px; font-size: 13.44px; font-family: sans-serif; transform: scaleX(0.903292)"></span></li><li><span style="left: 255.133px; top: 348.133px; font-size: 13.44px; font-family: sans-serif; transform: scaleX(0.903292)">Email Address</span><span style="left: 243.933px; top: 380.133px; font-size: 13.44px; font-family: sans-serif; transform: scaleX(0.884775)"></span><span style="left: 243.933px; top: 380.133px; font-size: 13.44px; font-family: sans-serif; transform: scaleX(0.884775)"></span></li></ul>
<span style="left: 243.933px; top: 380.133px; font-size: 13.44px; font-family: sans-serif; transform: scaleX(0.884775)">This is described in
</span><span style="left: 349.253px; top: 380.133px; font-size: 13.44px; font-family: sans-serif; transform: scaleX(0.947378)">http://docs.oasis</span><span style="left: 441.11999999999995px; top: 380.1333333333334px; font-size: 13.44px; font-family: sans-serif">-</span><span style="left: 243.933px; top: 399.013px; font-size: 13.44px; font-family: sans-serif; transform: scaleX(0.959646)">open.org/security/</span><span style="left: 346.373px; top: 399.013px; font-size: 13.44px; font-family: sans-serif; transform: scaleX(0.934572)">saml/v2.0/saml</span><span style="left: 429.91999999999996px; top: 399.0133333333334px; font-size: 13.44px; font-family: sans-serif">-</span><span style="left: 434.08px; top: 399.013px; font-size: 13.44px; font-family: sans-serif; transform: scaleX(0.917042)">core</span><span style="left: 458.1066666666666px; top: 399.0133333333334px; font-size: 13.44px; font-family: sans-serif">-</span><span style="left: 462.267px; top: 399.013px; font-size: 13.44px; font-family: sans-serif; transform: scaleX(0.91296)">2.0</span><span style="left: 478.90666666666664px; top: 399.0133333333334px; font-size: 13.44px; font-family: sans-serif">-</span><span style="left: 243.933px; top: 417.573px; font-size: 13.44px; font-family: sans-serif; transform: scaleX(0.926166)">os.pdf</span><span style="left: 280.733px; top: 417.573px; font-size: 13.44px; font-family: sans-serif; transform: scaleX(0.888562)">(page
14</span><span style="left: 327.813px; top: 417.573px; font-size: 13.44px; font-family: sans-serif; transform: scaleX(0.853073)">).</span><span style="left: 515.387px; top: 241.213px; font-size: 13.44px; font-family: sans-serif; transform: scaleX(0.936299)"><br>
</span></div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 9pt; color: rgb(0, 0, 0);">
<span style="left: 515.387px; top: 241.213px; font-size: 13.44px; font-family: sans-serif; transform: scaleX(0.936299)"><br>
</span></div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 9pt; color: rgb(0, 0, 0);">
<b><span style="left: 515.387px; top: 241.213px; font-size: 13.44px; font-family: sans-serif; transform: scaleX(0.936299)">CSOD validation steps:</span></b></div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 9pt; color: rgb(0, 0, 0);">
<span style="left: 515.387px; top: 241.213px; font-size: 13.44px; font-family: sans-serif; transform: scaleX(0.936299)">Verify the User information in the
</span><span style="left: 515.387px; top: 260.093px; font-size: 13.44px; font-family: sans-serif; transform: scaleX(0.863891)">Client's CSOD database. The User
</span><span style="left: 515.387px; top: 278.653px; font-size: 13.44px; font-family: sans-serif; transform: scaleX(0.900016)">must be an existing, Active User in
</span><span style="left: 515.387px; top: 297.213px; font-size: 13.44px; font-family: sans-serif; transform: scaleX(0.895768)">the Client's CSOD portal. Other</span><span style="left: 683.1333333333333px; top: 297.2133333333334px; font-size: 13.44px; font-family: sans-serif">w</span><span style="left: 692.773px; top: 297.213px; font-size: 13.44px; font-family: sans-serif; transform: scaleX(0.850048)">ise,
</span><span style="left: 515.387px; top: 316.093px; font-size: 13.44px; font-family: sans-serif; transform: scaleX(0.893286)">access is denied to the User</span></div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 9pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 9pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 9pt; color: rgb(0, 0, 0);">
<img size="40880" contenttype="image/png" style="max-width: 100%; user-select: none;" unselectable="on" tabindex="-1" data-outlook-trace="F:1|T:1" src="cid:7fc64695-971f-4aa2-9a64-f80daf61434d"><br>
</div>
<div style="font-family: Arial, Helvetica, sans-serif; font-size: 9pt; color: rgb(0, 0, 0);">
<br>
</div>
<div>
<div id="Signature">
<div>
<div></div>
<div></div>
<div></div>
<div style="font-family:Tahoma; font-size:13px">
<div class="BodyFragment"><font size="2">
<div class="PlainText">Thanks, </div>
<div class="PlainText">Shweta <br>
</div>
</font></div>
</div>
</div>
</div>
</div>
<div id="appendonsend"></div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Cantor, Scott <cantor.2@osu.edu><br>
<b>Sent:</b> Monday, June 15, 2020 8:57 AM<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Subject:</b> [External] Re: Cornerstone On Demand + SSO + custom attribute for user matching</font>
<div> </div>
</div>
<div class="BodyFragment"><font size="2"><span style="font-size:11pt;">
<div class="PlainText">[CAUTION: External email. Do not click links or open attachments unless verified. Send all suspicious email as an attachment to spam@northcarolina.edu<mailto:spam@northcarolina.edu>]<br>
<br>
<br>
On 6/12/20, 6:16 PM, "users on behalf of Shweta Kautia" <users-bounces@shibboleth.net on behalf of skautia@northcarolina.edu> wrote:<br>
<br>
> Has anyone set up SSO with CSOD, using EduPersonPrincipalName from assertion, matching on a custom attribute in<br>
> the system?<br>
<br>
They mapped in a custom Attribute when I integrated it, we had nothing we could use at the time that fit the use case for various reasons, but if EPPN had been appropriate for us, that could have been the one that we mapped in.<br>
<br>
There are a whole lot of problems with Cornerstone, but that wasn't one of them.<br>
<br>
-- Scott<br>
<br>
<br>
--<br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg">
https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font></div>
</body>
</html>