<div dir="ltr">Thanks for the suggestion. Upon consideration, I don't think this will work as is. The problem is that I believe the SP in question (SAP Concur) will uses the same entityID for both instances, so I don't think it's we can use it to distinguish between the two instances for the activation condition. Upon further reflection, I'm not sure how we're supposed to be able distinguish between their instances without something like an entityID difference. But maybe I'm missing something else.<div><br></div><div><br></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Thu, Mar 4, 2021 at 4:45 PM Lipscomb, Gary via users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-style:solid;border-left-color:rgb(204,204,204);padding-left:1ex">
<div lang="EN-AU">
<div class="gmail-m_4279354888395309419WordSection1">
<p class="MsoNormal"><span>Try something like this<u></u><u></u></span></p>
<p class="MsoNormal"><span><u></u> <u></u></span></p>
<p class="MsoNormal" style="margin-left:36pt"> <bean parent="shibboleth.SAML2AttributeSourcedGenerator"<u></u><u></u></p>
<p class="MsoNormal" style="margin-left:36pt"> p:format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress"<u></u><u></u></p>
<p class="MsoNormal" style="margin-left:36pt"> p:attributeSourceIds="#{ {'attrEmail_real'} }"><u></u><u></u></p>
<p class="MsoNormal" style="margin-left:36pt"> <property name="activationCondition"><u></u><u></u></p>
<p class="MsoNormal" style="margin-left:36pt"> <bean parent="shibboleth.Conditions.RelyingPartyId" c:candidates="#{{SP entityID}}" /><u></u><u></u></p>
<p class="MsoNormal" style="margin-left:36pt"> </property><u></u><u></u></p>
<p class="MsoNormal" style="margin-left:36pt"></bean><u></u><u></u></p>
<p class="MsoNormal"><span><u></u> <u></u></span></p>
<p class="MsoNormal"><span>Gary<u></u><u></u></span></p>
<p class="MsoNormal"><span><u></u> <u></u></span></p>
<p class="MsoNormal" style="margin-left:36pt"><b><span lang="EN-US">From:</span></b><span lang="EN-US"> users <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a>>
<b>On Behalf Of </b>Baron Fujimoto<br>
<b>Sent:</b> Friday, 5 March 2021 13:20<br>
<b>To:</b> Shib Users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
<b>Subject:</b> alternate attributeSourceIDs for a given nameid format<u></u><u></u></span></p>
<p class="MsoNormal" style="margin-left:36pt"><u></u> <u></u></p>
<div>
<div>
<div>
<div>
<div>
<div>
<p class="MsoNormal" style="margin-left:36pt">We have an SP that claims to need an emailAddress NameIDFormat. We can currently achieve this with an entry in our saml-nameid.xml conf file like:<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:36pt"><u></u> <u></u></p>
</div>
<div>
<div>
<p class="MsoNormal" style="margin-left:36pt"> <bean parent="shibboleth.SAML2AttributeSourcedGenerator"<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:36pt"> p:format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress"<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:36pt"> p:attributeSourceIds="#{ {'attrEmail_real'} }" /><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:36pt"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:36pt">However, for this SP now claims that for a separate instance of their SP, they need users with IDs that do not share the same domain name. We may be able to synthesize a new email-like attribute, say, attrEmail_2,
but is there a way to get use it as an alternate emailAddress NameIDFormat for this just this SP? E.g, something like<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:36pt"><u></u> <u></u></p>
</div>
<div>
<div>
<p class="MsoNormal" style="margin-left:36pt"> <bean parent="shibboleth.SAML2AttributeSourcedGenerator"<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:36pt"> p:format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress"<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:36pt"> p:attributeSourceIds="#{ {'attrEmail_synth'} }" /><u></u><u></u></p>
</div>
</div>
<div>
<p class="MsoNormal" style="margin-left:36pt"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:36pt">It seems like the nameid encoder(?) only pays attention to the format though, and not the attributeSourceId, and thus select one or other?<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:36pt"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:36pt">Perhaps some approach using an activation condition, or other suggestions or advice?<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:36pt"><u></u> <u></u></p>
</div>
<p class="MsoNormal" style="margin-left:36pt">-- <u></u><u></u></p>
<div>
<div>
<p class="MsoNormal" style="margin-left:36pt">Baron Fujimoto <<a href="mailto:baron@hawaii.edu" target="_blank">baron@hawaii.edu</a>> :: UH Information Technology Services<br>
minutas cantorum, minutas balorum, minutas carboratum desendus pantorum<u></u><u></u></p>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div><br clear="all"><div><br></div>-- <br><div dir="ltr" class="gmail_signature"><div dir="ltr">Baron Fujimoto <<a href="mailto:baron@hawaii.edu" target="_blank">baron@hawaii.edu</a>> :: UH Information Technology Services<br>minutas cantorum, minutas balorum, minutas carboratum desendus pantorum</div></div>