<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body>
    <div class="moz-cite-prefix">On 1/8/2021 11:31 AM, Cantor, Scott
      wrote:<br>
    </div>
    <blockquote type="cite"
      cite="mid:E7D5485D-B48F-4608-8B10-899CCDAC2DDA@osu.edu">
      <blockquote type="cite" style="color: #007cff;">
        <pre class="moz-quote-pre" wrap="">   Several external services uses this nameid, I will spend a lot of energy making every parties modify their SP.
</pre>
      </blockquote>
      <pre class="moz-quote-pre" wrap="">I have never heard of anything that <b class="moz-txt-star"><span class="moz-txt-tag">*</span>needs<span class="moz-txt-tag">*</span></b> a transient NameID in any Format. That doesn't really make a great deal of sense.
</pre>
    </blockquote>
    <p>Speaking of not making much sense, we had a pair of SPs that
      required (yes really) a NameIDFormat of transient but with a
      "real" value (our net ID). Both had invalid entity IDs (some text
      plus a GUID) as well, to round out the brokeneity.  Sort of the
      opposite of what's being asked here.</p>
    <p>I think one could work around the original request by defining a
      SAML2 NameID with the expected format string, and using an
      attribute for the value from a computedId attribute. You might be
      in trouble if they need to do any backchannel functions, though.<br>
    </p>
    <pre class="moz-signature" cols="72">-- 
%%  Christopher A. Bongaarts   %%  <a class="moz-txt-link-abbreviated" href="mailto:cab@umn.edu">cab@umn.edu</a>          %%
%%  OIT - Identity Management  %%  <a class="moz-txt-link-freetext" href="http://umn.edu/~cab">http://umn.edu/~cab</a>  %%
%%  University of Minnesota    %%  +1 (612) 625-1809    %%
</pre>
  </body>
</html>