<div dir="ltr"><div>I read the earlier thread on this list "Notice from Adobe about IdP SHA-1 certificates", and was following the instructions (<a href="https://helpx.adobe.com/enterprise/admin-guide.html/enterprise/using/set-up-identity.ug.html#migrateesaml">https://helpx.adobe.com/enterprise/admin-guide.html/enterprise/using/set-up-identity.ug.html#migrateesaml</a>) today. It seemed essentially to be like adding a new SP (loaded the new SP metadata, set up attribute release policies identical to the ones I used with the existing Adobe config).</div><div><br></div><div>When I get to the testing part it seems that something's behaving differently with the encoding of the nameid. We've been using the email based nameid that Adobe had requested, and with the existing SP config that seems to work just fine. I can see the nameid-as-email address being released in the logs. But when I test the new Adobe SP that nameid (which Adobe uses as the username) is scrambled.</div><div><br></div><div>With the current SP configuration "<a href="mailto:username@reed.edu">username@reed.edu</a>" is released, when I test the new configuration I can see in the logs that it's releasing a 32 character alphanumeric string.  And indeed the test result page reports that string as my username. </div><div><br></div><div>I can only imagine I'm missing something fairly obvious, but I've configured dozens of SPs before and never run into an issue like this. Any suggestions would be greatly appreciated!</div><div><br></div><div>Ben</div><div><br></div></div>