<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body>
    Right/wrong/in-different, our current Adobe/okta configuration in
    Shibboleth reference the following:<br>
    <br>
    <b>saml-nameid.xml</b><br>
    <br>
    <tt><bean parent="shibboleth.SAML2AttributeSourcedGenerator"</tt><tt><br>
    </tt><tt>      
      p:format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress"</tt><tt><br>
    </tt><tt>       p:attributeSourceIds="#{ {'AdobeEmail'} }" ></tt><tt><br>
    </tt><br>
    <b>attribute-filter.xml</b><br>
    <br>
    <tt><<a class="moz-txt-link-freetext" href="afp:AttributeRule">afp:AttributeRule</a> attributeID="AdobeEmail"></tt><tt><br>
    </tt><tt>       <<a class="moz-txt-link-freetext" href="afp:PermitValueRule">afp:PermitValueRule</a> xsi:type="basic:ANY" /></tt><tt><br>
    </tt><tt></<a class="moz-txt-link-freetext" href="afp:AttributeRule">afp:AttributeRule</a>></tt><tt><br>
    </tt><tt><br>
    </tt><tt><<a class="moz-txt-link-freetext" href="afp:AttributeRule">afp:AttributeRule</a> attributeID="AdobeFirstName"></tt><tt><br>
    </tt><tt>       <<a class="moz-txt-link-freetext" href="afp:PermitValueRule">afp:PermitValueRule</a> xsi:type="basic:ANY" /></tt><tt><br>
    </tt><tt></<a class="moz-txt-link-freetext" href="afp:AttributeRule">afp:AttributeRule</a>></tt><tt><br>
    </tt><tt><br>
    </tt><tt><<a class="moz-txt-link-freetext" href="afp:AttributeRule">afp:AttributeRule</a> attributeID="AdobeLastName"></tt><tt><br>
    </tt><tt>       <<a class="moz-txt-link-freetext" href="afp:PermitValueRule">afp:PermitValueRule</a> xsi:type="basic:ANY" /></tt><tt><br>
    </tt><tt></<a class="moz-txt-link-freetext" href="afp:AttributeRule">afp:AttributeRule</a>></tt><tt><br>
    </tt><br>
    Looking at the Adobe SAML configuration and the Adobe Admin tool
    documentation, I see no reference to what an attribute needs to be
    called or any mapping to what the IdP passes to Adobe.<br>
    <br>
    What are others passing?<br>
    <br>
    Thanks,<br>
    Don<br>
    <br>
    <br>
    <div class="moz-cite-prefix">On 7/21/20 2:28 PM, Lee Foltz wrote:<br>
    </div>
    <blockquote type="cite"
cite="mid:CAPcR9uSxdQ85ztDBxdhS_aT6G+0qUgXeBDJc8a-Fp=51Su56Bg@mail.gmail.com">
      <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
      <div dir="ltr">Yesterday I followed these instructions from
        Abobe and had to Add new IDP, which was just uploading our
        metadata again, then they provided a link to download or use URL
        to use Adobe new SP metadata with SHA-256 certificate.
        <div><a
href="https://urldefense.proofpoint.com/v2/url?u=https-3A__helpx.adobe.com_enterprise_using_set-2Dup-2Didentity.html-23migrateesaml&d=DwMFaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=Pa2DB88IW_s2TyLfktHtWA&m=XrDZ92WjqteMdmQTAl8jpmptdljOQmhYgdS8LdXj4M8&s=skrs6JyaDISVRDB8JrV7-2DX-Pa2t5d-tdQWiM1ixFU&e="
            moz-do-not-send="true">https://helpx.adobe.com/enterprise/using/set-up-identity.html#migrateesaml</a><br>
        </div>
        <div><br>
        </div>
        <div>There is also a Test feature to test the new IDP setup with
          the new Adobe SP metadata, you can also revert changes and
          roll back to other IDP still configured (SHA-1) if your new
          setup doesn't work.</div>
        <div>We tested and had no issues with Federated Login on new
          setup with new Adobe SP metadata.</div>
        <div><br>
        </div>
        <div>Hope this helps everyone.</div>
      </div>
      <br>
      <div class="gmail_quote">
        <div dir="ltr" class="gmail_attr">On Tue, Jul 21, 2020 at 9:43
          AM Cantor, Scott <<a href="mailto:cantor.2@osu.edu"
            moz-do-not-send="true">cantor.2@osu.edu</a>> wrote:<br>
        </div>
        <blockquote class="gmail_quote" style="margin:0px 0px 0px
          0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">On
          7/21/20, 9:38 AM, "users on behalf of Peter Schober" <<a
            href="mailto:users-bounces@shibboleth.net" target="_blank"
            moz-do-not-send="true">users-bounces@shibboleth.net</a> on
          behalf of <a href="mailto:peter.schober@univie.ac.at"
            target="_blank" moz-do-not-send="true">peter.schober@univie.ac.at</a>>
          wrote:<br>
          <br>
          >    I'll definitively be keeping a reference to this
          thread handy as I<br>
          >    feel I'll be needing it in the coming months.<br>
          <br>
          This topic comes up nearly every ACAMP with no real solution,
          but we need some kind of neutral venue for information sharing
          that we can use to post this sort of knowledge that people
          will see.<br>
          <br>
          -- Scott<br>
          <br>
          <br>
          -- <br>
          For Consortium Member technical support, see <a
href="https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.shibboleth.net_confluence_x_coFAAg&d=DwMFaQ&c=eLbWYnpnzycBCgmb7vCI4uqNEB9RSjOdn_5nBEmmeq0&r=Pa2DB88IW_s2TyLfktHtWA&m=XrDZ92WjqteMdmQTAl8jpmptdljOQmhYgdS8LdXj4M8&s=wxUvGKdwNA72T8Q0NE5MQ9WpPHF_fJwvBJk_aL5mmto&e="
            rel="noreferrer" target="_blank" moz-do-not-send="true">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
          To unsubscribe from this list send an email to <a
            href="mailto:users-unsubscribe@shibboleth.net"
            target="_blank" moz-do-not-send="true">users-unsubscribe@shibboleth.net</a><br>
        </blockquote>
      </div>
      <br clear="all">
      <div><br>
      </div>
      -- <br>
      <div dir="ltr" class="gmail_signature">
        <div dir="ltr">
          <div>
            <div>Lee Foltz</div>
            <div>Oakland University - UTS</div>
            <div>Senior Identity and Access Management Engineer</div>
            <div> </div>
            <div>248-370-2675</div>
          </div>
        </div>
      </div>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
    </blockquote>
    <br>
    <pre class="moz-signature" cols="72">-- 
D o n a l d   L o h r
I n f o r m a t i o n   S y s t e m s
J a m e s   M a d i s o n   U n i v e r s i t y
5 4 0 . 5 6 8 . 3 7 3 0
</pre>
  </body>
</html>