<div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr">I was able to script an attribute, attrEmail_aberrant, suitable for this SP, but ran into an XML parsing error trying to use it via an activation condition in saml-nameid.xml with the following entry:</div><div dir="ltr"><div><br></div><div><div>        <bean parent="shibboleth.SAML2AttributeSourcedGenerator"</div><div>                p:format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress"</div><div>                p:attributeSourceIds="#{ {'attrEmail_aberrant'} }"</div><div>            <property name="activationCondition"></div><div>                <bean parent="shibboleth.Conditions.RelyingPartyId" c:candidate="SP_entityID_aberrant" /></div><div>            </property></div><div>        </bean></div></div><div><br></div><div>Error when I reload:</div><div><br></div><div><div>ERROR [net.shibboleth.utilities.java.support.service.AbstractReloadableService:231] - Service 'shibboleth.NameIdentifierGenerationService': Reload for shibboleth.NameIdentifierGenerationService failed</div><div>net.shibboleth.utilities.java.support.service.ServiceException: org.springframework.beans.factory.xml.XmlBeanDefinitionStoreException: Line 64 in XML document from file [/home/shib/idp/conf/saml-nameid.xml] is invalid; nested exception is org.xml.sax.SAXParseException; lineNumber: 64; columnNumber: 13; Element type "bean" must be followed by either attribute specifications, ">" or "/>".</div></div></div></div></div></div></div></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Wed, Mar 10, 2021 at 9:06 AM Cantor, Scott <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-style:solid;border-left-color:rgb(204,204,204);padding-left:1ex">On 3/10/21, 1:03 PM, "users on behalf of Baron Fujimoto" <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:baron@hawaii.edu" target="_blank">baron@hawaii.edu</a>> wrote:<br>
<br>
>    I'm afraid my grasp of IdP-initiated SPs is poor and I don't yet have an inkling how we might begin to<br>
> implement these possibilities without more explicit documentation or examples.<br>
<br>
That's the benefit of membership, to be brutally frank.<br>
<br>
>    Getting back to the original suggestion by Gary Lipscomb, may we can kludge that after all, assuming we can<br>
> have multiple SAML2AttributeSourcedGenerator beans in saml-nameid.xml that use result in the same nameid<br>
> format, but use different attributeSourceID. If so, would these beans be order dependent on a first match basis<br>
> (like metadata?). Ie. something like this?<br>
<br>
Yes, that is probably the best fix for this issue, just release the unusual source attribute to just that SP and then it won't ever run successfully for any other, generators just fall through if they have nothing to operate on.<br>
<br>
-- Scott<br>
<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div><br clear="all"><div><br></div>-- <br><div dir="ltr" class="gmail_signature"><div dir="ltr">Baron Fujimoto <<a href="mailto:baron@hawaii.edu" target="_blank">baron@hawaii.edu</a>> :: UH Information Technology Services<br>minutas cantorum, minutas balorum, minutas carboratum desendus pantorum</div></div>