<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
</head>
<body>
<div class="moz-cite-prefix">On 2/8/2021 11:59 AM, Donald Lohr
wrote:<br>
</div>
<blockquote type="cite"
cite="mid:93822984-4d41-a953-3e26-18ffe3a2f00d@jmu.edu">When using
the aacli tool, the top line of the results is:<br>
<br>
<?xml version="1.0" encoding="UTF-8"?><saml2:Assertion
xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" ID="<b>_Removed
the returned value</b>" IssueInstant="2021-02-08T17:22:29.862Z"
Version="2.0"><br>
<br>
My question is about the ID value. I've removed the actual ID
returned (from above) when I ran the aacli tool. But its value is
different for each user for the same SP and different for each SP.
The returned ID values are 31 characters starting with an
underscore and then alpha-numeric.<br>
<br>
Not sure what to search on in the Shibboleth wiki to even find
what these values mean and what they are for.<br>
<br>
Thanks, if anyone could point me to said documents. <br>
</blockquote>
<p>It's a SAMLism, not specific to Shib/AACLI:<br>
</p>
<p><a moz-do-not-send="true"
href="https://docs.oasis-open.org/security/saml/v2.0/saml-core-2.0-os.pdf">https://docs.oasis-open.org/security/saml/v2.0/saml-core-2.0-os.pdf</a></p>
<blockquote>
<p><span style="left: 120.167px; top: 899.052px; font-size:
21.6667px; font-family: sans-serif; transform:
scaleX(0.998985);">1.3.4 </span><span style="left: 180.167px;
top: 899.052px; font-size: 21.6667px; font-family: sans-serif;
transform: scaleX(1.02176);">ID an</span><span style="left:
233.167px; top: 899.052px; font-size: 21.6667px; font-family:
sans-serif; transform: scaleX(1.03337);">d ID Refer</span><span
style="left: 335px; top: 899.052px; font-size: 21.6667px;
font-family: sans-serif; transform: scaleX(1.05135);">ence
Values</span><span style="left: 120.167px; top: 940.412px;
font-size: 16.6667px; font-family: sans-serif; transform:
scaleX(1.003);"><br>
</span></p>
<p><span style="left: 120.167px; top: 940.412px; font-size:
16.6667px; font-family: sans-serif; transform: scaleX(1.003);">The
</span><span style="left: 153.5px; top: 940.412px; font-size:
16.6667px; font-family: sans-serif; transform:
scaleX(1.0676);">xs:ID</span><span style="left: 194.167px;
top: 940.412px; font-size: 16.6667px; font-family: sans-serif;
transform: scaleX(0.995744);"> simple type is used to declare
SAML identifiers for assertions, requests,</span><span
style="left: 724.333px; top: 940.412px; font-size: 16.6667px;
font-family: sans-serif; transform: scaleX(1.00347);"> and
responses. Values</span><span style="left: 120.167px; top:
959.579px; font-size: 16.6667px; font-family: sans-serif;
transform: scaleX(1);"> declare</span><span style="left:
174.667px; top: 959.579px; font-size: 16.6667px; font-family:
sans-serif; transform: scaleX(0.998801);">d to be of</span><span
style="left: 243.667px; top: 959.579px; font-size: 16.6667px;
font-family: sans-serif; transform: scaleX(0.984056);"> type </span><span
style="left: 283.667px; top: 959.579px; font-size: 16.6667px;
font-family: sans-serif; transform: scaleX(1.07287);">xs:ID</span><span
style="left: 324.333px; top: 959.579px; font-size: 16.6667px;
font-family: sans-serif; transform: scaleX(0.996883);"> in
this specifica</span><span style="left: 441.333px; top:
959.579px; font-size: 16.6667px; font-family: sans-serif;
transform: scaleX(0.995597);">tion MUST satisfy the following
properties</span><span style="left: 746.167px; top: 959.579px;
font-size: 16.6667px; font-family: sans-serif; transform:
scaleX(0.991236);"> in addition to those</span><span
style="left: 120.167px; top: 978.745px; font-size: 16.6667px;
font-family: sans-serif; transform: scaleX(0.993909);">
imposed by the definition of the </span><span style="left:
354px; top: 978.745px; font-size: 16.6667px; font-family:
sans-serif; transform: scaleX(1.0676);">xs:ID</span><span
style="left: 394.5px; top: 978.745px; font-size: 16.6667px;
font-family: sans-serif; transform: scaleX(0.98682);"> type
itself:</span></p>
<p><span style="left: 394.5px; top: 978.745px; font-size:
16.6667px; font-family: sans-serif; transform:
scaleX(0.98682);"></span><span style="left: 143.667px; top:
1004.22px; font-size: 16.6667px; font-family: sans-serif;">•</span><span
style="left: 162.667px; top: 1004.41px; font-size: 16.6667px;
font-family: sans-serif; transform: scaleX(0.990039);">Any
party that assigns</span><span style="left: 324.833px; top:
1004.41px; font-size: 16.6667px; font-family: sans-serif;
transform: scaleX(0.99201);"> an identifier MUST ensure that
there is negligible probability that that party or </span><span
style="left: 162.667px; top: 1024.41px; font-size: 16.6667px;
font-family: sans-serif; transform: scaleX(0.989854);">any
other party will accidentally assign the sa</span><span
style="left: 492.5px; top: 1024.41px; font-size: 16.6667px;
font-family: sans-serif; transform: scaleX(0.997068);">me
identifier to a different data object.</span><span
style="left: 143.667px; top: 1053.05px; font-size: 16.6667px;
font-family: sans-serif;"><br>
</span></p>
<p><span style="left: 143.667px; top: 1053.05px; font-size:
16.6667px; font-family: sans-serif;">•</span><span
style="left: 162.667px; top: 1053.25px; font-size: 16.6667px;
font-family: sans-serif; transform: scaleX(1.00416);">Where a
data obje</span><span style="left: 299px; top: 1053.25px;
font-size: 16.6667px; font-family: sans-serif; transform:
scaleX(1.00021);">ct declares</span><span style="left:
379.5px; top: 1053.25px; font-size: 16.6667px; font-family:
sans-serif; transform: scaleX(0.997574);"> that it has a
particular identifier, there MUST</span><span style="left:
708.5px; top: 1053.25px; font-size: 16.6667px; font-family:
sans-serif; transform: scaleX(0.991882);"> be exactly one such
</span><span style="left: 162.667px; top: 1073.25px; font-size:
16.6667px; font-family: sans-serif; transform: scaleX(1);">declara</span><span
style="left: 217.167px; top: 1073.25px; font-size: 16.6667px;
font-family: sans-serif; transform: scaleX(0.987831);">tion.</span><span
style="left: 120.167px; top: 1108.41px; font-size: 16.6667px;
font-family: sans-serif; transform: scaleX(0.994301);"><br>
</span></p>
<p><span style="left: 120.167px; top: 1108.41px; font-size:
16.6667px; font-family: sans-serif; transform:
scaleX(0.994301);">The mechanism by which a SAML system entity
ensure</span><span style="left: 527px; top: 1108.41px;
font-size: 16.6667px; font-family: sans-serif; transform:
scaleX(0.994564);">s that the identifier is unique is left to
the </span><span style="left: 120.167px; top: 1126.75px;
font-size: 16.6667px; font-family: sans-serif; transform:
scaleX(0.997316);">implementation. In the case that a random
or </span><span style="left: 454.5px; top: 1126.75px;
font-size: 16.6667px; font-family: sans-serif; transform:
scaleX(0.995352);">pseudorandom</span><span style="left:
565.5px; top: 1126.75px; font-size: 16.6667px; font-family:
sans-serif; transform: scaleX(0.991681);"> technique is
employed, the probability of two </span><span style="left:
120.167px; top: 1145.25px; font-size: 16.6667px; font-family:
sans-serif; transform: scaleX(0.994351);">randomly chosen
identifiers being identical MUST</span><span style="left:
484px; top: 1145.25px; font-size: 16.6667px; font-family:
sans-serif; transform: scaleX(0.994091);"> be less than or
equal to 2</span><span style="left: 674.5px; top: 1145.25px;
font-size: 9.66667px; font-family: sans-serif; transform:
scaleX(0.922603);">-128</span><span style="left: 694px; top:
1145.25px; font-size: 16.6667px; font-family: sans-serif;
transform: scaleX(0.994993);"> and SHOULD</span><span
style="left: 800px; top: 1145.25px; font-size: 16.6667px;
font-family: sans-serif; transform: scaleX(0.995062);"> be
less than </span><span style="left: 120.167px; top:
1163.58px; font-size: 16.6667px; font-family: sans-serif;
transform: scaleX(0.994064);">or equal to 2</span><span
style="left: 212.167px; top: 1163.58px; font-size: 9.66667px;
font-family: sans-serif; transform: scaleX(0.922603);">-160</span><span
style="left: 231.5px; top: 1163.58px; font-size: 16.6667px;
font-family: sans-serif; transform: scaleX(0.995719);">. This
requirement MAY be met by encoding a randomly chosen value
between 128 and </span><span style="left: 231.5px; top:
1163.58px; font-size: 16.6667px; font-family: sans-serif;
transform: scaleX(0.995719);"><span style="left: 120.167px;
top: 120.412px; font-size: 16.6667px; font-family:
sans-serif; transform: scaleX(0.995767);">160 bits in
length. The encoding</span><span style="left: 355px; top:
120.412px; font-size: 16.6667px; font-family: sans-serif;
transform: scaleX(0.998322);"> must conform to the rules
defining the </span><span style="left: 642.5px; top:
120.412px; font-size: 16.6667px; font-family: sans-serif;
transform: scaleX(1.0676);">xs:ID</span><span style="left:
687.667px; top: 120.412px; font-size: 16.6667px;
font-family: sans-serif; transform: scaleX(0.987603);">datatype.</span><span
style="left: 755.333px; top: 120.412px; font-size:
16.6667px; font-family: sans-serif; transform:
scaleX(0.993665);"> A pseudorandom</span><span style="left:
120.167px; top: 138.912px; font-size: 16.6667px;
font-family: sans-serif; transform: scaleX(0.995005);">
generator MUST be seeded with unique material in order to
ensure the desired uniqueness</span><span style="left:
787.333px; top: 138.912px; font-size: 16.6667px;
font-family: sans-serif; transform: scaleX(0.994073);">
properties</span><span style="left: 120.167px; top:
157.412px; font-size: 16.6667px; font-family: sans-serif;
transform: scaleX(0.995874);"> between different systems.</span></span></p>
</blockquote>
<pre class="moz-signature" cols="72">--
%% Christopher A. Bongaarts %% <a class="moz-txt-link-abbreviated" href="mailto:cab@umn.edu">cab@umn.edu</a> %%
%% OIT - Identity Management %% <a class="moz-txt-link-freetext" href="http://umn.edu/~cab">http://umn.edu/~cab</a> %%
%% University of Minnesota %% +1 (612) 625-1809 %%
</pre>
</body>
</html>