<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body>
    <div class="moz-cite-prefix">On 2/8/2021 11:59 AM, Donald Lohr
      wrote:<br>
    </div>
    <blockquote type="cite"
      cite="mid:93822984-4d41-a953-3e26-18ffe3a2f00d@jmu.edu">When using
      the aacli tool, the top line of the results is:<br>
      <br>
      <?xml version="1.0" encoding="UTF-8"?><saml2:Assertion
      xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" ID="<b>_Removed
        the returned value</b>" IssueInstant="2021-02-08T17:22:29.862Z"
      Version="2.0"><br>
      <br>
      My question is about the ID value. I've removed the actual ID
      returned (from above) when I ran the aacli tool. But its value is
      different for each user for the same SP and different for each SP.
      The returned ID values are 31 characters starting with an
      underscore and then alpha-numeric.<br>
      <br>
      Not sure what to search on in the Shibboleth wiki to even find
      what these values mean and what they are for.<br>
      <br>
      Thanks, if anyone could point me to said documents. <br>
    </blockquote>
    <p>It's a SAMLism, not specific to Shib/AACLI:<br>
    </p>
    <p><a moz-do-not-send="true"
href="https://docs.oasis-open.org/security/saml/v2.0/saml-core-2.0-os.pdf">https://docs.oasis-open.org/security/saml/v2.0/saml-core-2.0-os.pdf</a></p>
    <blockquote>
      <p><span style="left: 120.167px; top: 899.052px; font-size:
          21.6667px; font-family: sans-serif; transform:
          scaleX(0.998985);">1.3.4 </span><span style="left: 180.167px;
          top: 899.052px; font-size: 21.6667px; font-family: sans-serif;
          transform: scaleX(1.02176);">ID an</span><span style="left:
          233.167px; top: 899.052px; font-size: 21.6667px; font-family:
          sans-serif; transform: scaleX(1.03337);">d ID Refer</span><span
          style="left: 335px; top: 899.052px; font-size: 21.6667px;
          font-family: sans-serif; transform: scaleX(1.05135);">ence
          Values</span><span style="left: 120.167px; top: 940.412px;
          font-size: 16.6667px; font-family: sans-serif; transform:
          scaleX(1.003);"><br>
        </span></p>
      <p><span style="left: 120.167px; top: 940.412px; font-size:
          16.6667px; font-family: sans-serif; transform: scaleX(1.003);">The
        </span><span style="left: 153.5px; top: 940.412px; font-size:
          16.6667px; font-family: sans-serif; transform:
          scaleX(1.0676);">xs:ID</span><span style="left: 194.167px;
          top: 940.412px; font-size: 16.6667px; font-family: sans-serif;
          transform: scaleX(0.995744);"> simple type is used to declare
          SAML identifiers for assertions, requests,</span><span
          style="left: 724.333px; top: 940.412px; font-size: 16.6667px;
          font-family: sans-serif; transform: scaleX(1.00347);"> and
          responses. Values</span><span style="left: 120.167px; top:
          959.579px; font-size: 16.6667px; font-family: sans-serif;
          transform: scaleX(1);"> declare</span><span style="left:
          174.667px; top: 959.579px; font-size: 16.6667px; font-family:
          sans-serif; transform: scaleX(0.998801);">d to be of</span><span
          style="left: 243.667px; top: 959.579px; font-size: 16.6667px;
          font-family: sans-serif; transform: scaleX(0.984056);"> type </span><span
          style="left: 283.667px; top: 959.579px; font-size: 16.6667px;
          font-family: sans-serif; transform: scaleX(1.07287);">xs:ID</span><span
          style="left: 324.333px; top: 959.579px; font-size: 16.6667px;
          font-family: sans-serif; transform: scaleX(0.996883);"> in
          this specifica</span><span style="left: 441.333px; top:
          959.579px; font-size: 16.6667px; font-family: sans-serif;
          transform: scaleX(0.995597);">tion MUST satisfy the following
          properties</span><span style="left: 746.167px; top: 959.579px;
          font-size: 16.6667px; font-family: sans-serif; transform:
          scaleX(0.991236);"> in addition to those</span><span
          style="left: 120.167px; top: 978.745px; font-size: 16.6667px;
          font-family: sans-serif; transform: scaleX(0.993909);">
          imposed by the definition of the </span><span style="left:
          354px; top: 978.745px; font-size: 16.6667px; font-family:
          sans-serif; transform: scaleX(1.0676);">xs:ID</span><span
          style="left: 394.5px; top: 978.745px; font-size: 16.6667px;
          font-family: sans-serif; transform: scaleX(0.98682);"> type
          itself:</span></p>
      <p><span style="left: 394.5px; top: 978.745px; font-size:
          16.6667px; font-family: sans-serif; transform:
          scaleX(0.98682);"></span><span style="left: 143.667px; top:
          1004.22px; font-size: 16.6667px; font-family: sans-serif;">•</span><span
          style="left: 162.667px; top: 1004.41px; font-size: 16.6667px;
          font-family: sans-serif; transform: scaleX(0.990039);">Any
          party that assigns</span><span style="left: 324.833px; top:
          1004.41px; font-size: 16.6667px; font-family: sans-serif;
          transform: scaleX(0.99201);"> an identifier MUST ensure that
          there is negligible probability that that party or </span><span
          style="left: 162.667px; top: 1024.41px; font-size: 16.6667px;
          font-family: sans-serif; transform: scaleX(0.989854);">any
          other party will accidentally assign the sa</span><span
          style="left: 492.5px; top: 1024.41px; font-size: 16.6667px;
          font-family: sans-serif; transform: scaleX(0.997068);">me
          identifier to a different data object.</span><span
          style="left: 143.667px; top: 1053.05px; font-size: 16.6667px;
          font-family: sans-serif;"><br>
        </span></p>
      <p><span style="left: 143.667px; top: 1053.05px; font-size:
          16.6667px; font-family: sans-serif;">•</span><span
          style="left: 162.667px; top: 1053.25px; font-size: 16.6667px;
          font-family: sans-serif; transform: scaleX(1.00416);">Where a
          data obje</span><span style="left: 299px; top: 1053.25px;
          font-size: 16.6667px; font-family: sans-serif; transform:
          scaleX(1.00021);">ct declares</span><span style="left:
          379.5px; top: 1053.25px; font-size: 16.6667px; font-family:
          sans-serif; transform: scaleX(0.997574);"> that it has a
          particular identifier, there MUST</span><span style="left:
          708.5px; top: 1053.25px; font-size: 16.6667px; font-family:
          sans-serif; transform: scaleX(0.991882);"> be exactly one such
        </span><span style="left: 162.667px; top: 1073.25px; font-size:
          16.6667px; font-family: sans-serif; transform: scaleX(1);">declara</span><span
          style="left: 217.167px; top: 1073.25px; font-size: 16.6667px;
          font-family: sans-serif; transform: scaleX(0.987831);">tion.</span><span
          style="left: 120.167px; top: 1108.41px; font-size: 16.6667px;
          font-family: sans-serif; transform: scaleX(0.994301);"><br>
        </span></p>
      <p><span style="left: 120.167px; top: 1108.41px; font-size:
          16.6667px; font-family: sans-serif; transform:
          scaleX(0.994301);">The mechanism by which a SAML system entity
          ensure</span><span style="left: 527px; top: 1108.41px;
          font-size: 16.6667px; font-family: sans-serif; transform:
          scaleX(0.994564);">s that the identifier is unique is left to
          the </span><span style="left: 120.167px; top: 1126.75px;
          font-size: 16.6667px; font-family: sans-serif; transform:
          scaleX(0.997316);">implementation. In the case that a random
          or </span><span style="left: 454.5px; top: 1126.75px;
          font-size: 16.6667px; font-family: sans-serif; transform:
          scaleX(0.995352);">pseudorandom</span><span style="left:
          565.5px; top: 1126.75px; font-size: 16.6667px; font-family:
          sans-serif; transform: scaleX(0.991681);"> technique is
          employed, the probability of two </span><span style="left:
          120.167px; top: 1145.25px; font-size: 16.6667px; font-family:
          sans-serif; transform: scaleX(0.994351);">randomly chosen
          identifiers being identical MUST</span><span style="left:
          484px; top: 1145.25px; font-size: 16.6667px; font-family:
          sans-serif; transform: scaleX(0.994091);"> be less than or
          equal to 2</span><span style="left: 674.5px; top: 1145.25px;
          font-size: 9.66667px; font-family: sans-serif; transform:
          scaleX(0.922603);">-128</span><span style="left: 694px; top:
          1145.25px; font-size: 16.6667px; font-family: sans-serif;
          transform: scaleX(0.994993);"> and SHOULD</span><span
          style="left: 800px; top: 1145.25px; font-size: 16.6667px;
          font-family: sans-serif; transform: scaleX(0.995062);"> be
          less than </span><span style="left: 120.167px; top:
          1163.58px; font-size: 16.6667px; font-family: sans-serif;
          transform: scaleX(0.994064);">or equal to 2</span><span
          style="left: 212.167px; top: 1163.58px; font-size: 9.66667px;
          font-family: sans-serif; transform: scaleX(0.922603);">-160</span><span
          style="left: 231.5px; top: 1163.58px; font-size: 16.6667px;
          font-family: sans-serif; transform: scaleX(0.995719);">. This
          requirement MAY be met by encoding a randomly chosen value
          between 128 and </span><span style="left: 231.5px; top:
          1163.58px; font-size: 16.6667px; font-family: sans-serif;
          transform: scaleX(0.995719);"><span style="left: 120.167px;
            top: 120.412px; font-size: 16.6667px; font-family:
            sans-serif; transform: scaleX(0.995767);">160 bits in
            length. The encoding</span><span style="left: 355px; top:
            120.412px; font-size: 16.6667px; font-family: sans-serif;
            transform: scaleX(0.998322);"> must conform to the rules
            defining the </span><span style="left: 642.5px; top:
            120.412px; font-size: 16.6667px; font-family: sans-serif;
            transform: scaleX(1.0676);">xs:ID</span><span style="left:
            687.667px; top: 120.412px; font-size: 16.6667px;
            font-family: sans-serif; transform: scaleX(0.987603);">datatype.</span><span
            style="left: 755.333px; top: 120.412px; font-size:
            16.6667px; font-family: sans-serif; transform:
            scaleX(0.993665);"> A pseudorandom</span><span style="left:
            120.167px; top: 138.912px; font-size: 16.6667px;
            font-family: sans-serif; transform: scaleX(0.995005);">
            generator MUST be seeded with unique material in order to
            ensure the desired uniqueness</span><span style="left:
            787.333px; top: 138.912px; font-size: 16.6667px;
            font-family: sans-serif; transform: scaleX(0.994073);">
            properties</span><span style="left: 120.167px; top:
            157.412px; font-size: 16.6667px; font-family: sans-serif;
            transform: scaleX(0.995874);"> between different systems.</span></span></p>
    </blockquote>
    <pre class="moz-signature" cols="72">-- 
%%  Christopher A. Bongaarts   %%  <a class="moz-txt-link-abbreviated" href="mailto:cab@umn.edu">cab@umn.edu</a>          %%
%%  OIT - Identity Management  %%  <a class="moz-txt-link-freetext" href="http://umn.edu/~cab">http://umn.edu/~cab</a>  %%
%%  University of Minnesota    %%  +1 (612) 625-1809    %%
</pre>
  </body>
</html>