<div dir="ltr">Yes I use external authentication but I put just principal name into request attribute like:<br><span style="color:rgb(0,0,0);font-family:Consolas,"Bitstream Vera Sans Mono","Courier New",Courier,monospace;font-size:14px;white-space:nowrap">request.setAttribute(ExternalAuthentication.PRINCIPAL_NAME_KEY, username);<br></span>through documentation, I will need subject canonicalization if I use a Subject as authentication result</div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">Am Sa., 5. Juni 2021 um 00:02 Uhr schrieb Peter Schober <<a href="mailto:peter.schober@univie.ac.at">peter.schober@univie.ac.at</a>>:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">* Youssef Ait Laydi <<a href="mailto:youssef.aitlaydi@gmail.com" target="_blank">youssef.aitlaydi@gmail.com</a>> [2021-06-04 23:21]:<br>
> <AttributeDefinition id="mail" xsi:type="PrincipalName"><br>
> <AttributeEncoder xsi:type="SAML1String"<br>
> name="urn:mace:dir:attribute-def:mail" />        <AttributeEncoder<br>
> xsi:type="SAML2String" name="urn:oid:1.3.6.1.4.1.5923.1.1.1.1"<br>
> friendlyName="mail" />    </AttributeDefinition><br>
<br>
I don't think (and your logs confirm) that this isn't sufficient to<br>
get at the value from your external authentication mechanism.<br>
<br>
> And this configuration on *relying-party.xml*<br>
<br>
There's not need to override the nameIDFormatPrecedence when the<br>
metadata for the SP already specifies the desired NameIDFormat.<br>
(If in doubt see the Format selection part of the IDP documentation.)<br>
<br>
> I don't know how to get attributeSourceIds?<br>
<br>
Well, you managed to create your own external authentication method so<br>
I guess you'll just have to continue reading the documentation to<br>
learn about subject canonicalization and then how to pull the desired<br>
info into an attribute in your resolver.<br>
<br>
> WARN [org.opensaml.saml.common.binding.SAMLBindingSupport:93] - Relay state<br>
> exceeds 80 bytes: {"loginEmail":"<a href="mailto:test_sso@example.com" target="_blank">test_sso@example.com</a><br>
> ","loginType":"CONFIRMATION","redirect":"<br>
> <a href="https://app.hubspot.com/settings-sso-confirm" rel="noreferrer" target="_blank">https://app.hubspot.com/settings-sso-confirm</a>","rememberLogin":false}<br>
<br>
I have no idea what exaclty is the value of your RelayState from the<br>
line above but you can as far as "Relay state exceeds 80 bytes" goes<br>
you can ignore it.<br>
<br>
-peter<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div><br clear="all"><div><br></div>-- <br><div dir="ltr" class="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div><span style="font-size:12.8px">Software Engineer</span></div><div>Oracle Certified Professional Java SE 6 Programmer</div><div>Tel: 0674-931593</div><div><br></div></div></div></div></div>