<div dir="ltr">I'm attempting to add a new SP to our Shib 4 instance but I keep running into the error referenced in the subject:<br><br><blockquote style="margin:0 0 0 40px;border:none;padding:0px"><?xml version="1.0" encoding="UTF-8"?><samlp:AuthnRequest xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol" AssertionConsumerServiceURL="<a href="https://signin.app.cayuse.com/saml/SSO">https://signin.app.cayuse.com/saml/SSO</a>" Destination="<a href="https://our.idp.edu/idp/profile/SAML2/Redirect/SSO">https://our.idp.edu/idp/profile/SAML2/Redirect/SSO</a>" ID="CAYUSE_ec3bdf1a-0d99-49cf-bfc4-0945d16b572c" IssueInstant="2021-06-09T15:04:36Z" ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Version="2.0" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"><br>    <saml:Issuer><a href="https://signin.app.cayuse.com/saml/metadata">https://signin.app.cayuse.com/saml/metadata</a></saml:Issuer><br>    <samlp:NameIDPolicy AllowCreate="true" Format="urn:mace:shibboleth:1.0:nameIdentifier"/><br></samlp:AuthnRequest><br>2021-06-09 11:04:38,288 - WARN [org.opensaml.saml.saml2.profile.impl.AddNameIDToSubjects:334] - [a.b.c.d] - Profile Action AddNameIDToSubjects: Request specified use of an unsupportable identifier format: urn:mace:shibboleth:1.0:nameIdentifier<br>2021-06-09 11:04:38,290 - WARN [org.opensaml.profile.action.impl.LogEvent:101] - [a.b.c.d] - A non-proceed event occurred while processing the request: InvalidNameIDPolicy</blockquote><br><div>The SP is an InCommon member so I'm using their metadata that's in the InCommon feed. We contacted their support and said that we need to configure the NameID and added:<br><br></div><blockquote style="margin:0 0 0 40px;border:none;padding:0px"><div>The following is a list of attributes we support:</div><div><br></div><div>username-mapping-attr-names: |</div><div>      urn:oid:0.9.2342.19200300.100.1.1,</div><div>      urn:oid:1.3.6.1.4.1.5923.1.1.1.6,</div><div>      urn:oid:1.3.6.1.4.1.5923.1.1.1.10,</div><div>      urn:mace:dir:attribute-def:uid,</div><div>      urn:mace:dir:attribute-def:eduPersonPrincipalName,</div><div>      urn:oasis:names:tc:SAML:attribute:subject-id,</div><div>      urn:oasis:names:tc:SAML:2.0:nameid-format:persistent,</div><div>      <a href="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name">http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name</a>,</div><div>      <a href="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier">http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier</a>,</div><div>      <a href="http://schemas.microsoft.com/identity/claims/objectidentifier">http://schemas.microsoft.com/identity/claims/objectidentifier</a>,</div><div>      urn:oid:1.3.6.1.4.1.5923.1.1.1.2</div><div><br></div><div># Look for email in the following SAML attrs (if username not found), in order of first listed to last. CSV attr-names, whitespace OK.</div><div>email-mapping-attr-names: |</div><div>      urn:oid:0.9.2342.19200300.100.1.3,</div><div>      urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress,</div><div>      <a href="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress">http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress</a></div></blockquote><div><br>I was hoping that resolving it would be as simple as configuring the NameID in saml-nameid.xml, which I did as follows (uid is urn:oid:0.9.2342.19200300.100.1.1, one of the attributes they said they support):<br><br></div><blockquote style="margin:0 0 0 40px;border:none;padding:0px"><div><bean parent="shibboleth.SAML2AttributeSourcedGenerator"</div><div>    p:format="urn:oasis:names:tc:SAML:2.0:nameid-format:persistent"</div><div>    p:attributeSourceIds="#{ {'uid'} }"></div><div>    <property name="activationCondition"></div><div>        <bean parent="shibboleth.Conditions.RelyingPartyId" c:candidate="<a href="https://signin.app.cayuse.com/saml/metadata">https://signin.app.cayuse.com/saml/metadata</a>" /></div><div>    </property></div><div></bean></div></blockquote><div><br>I've successfully configured other SPs to use 

urn:oasis:names:tc:SAML:2.0:nameid-format:persistent in the same way, but unfortunately, I'm still running into the problem. 

The NameID format urn:mace:shibboleth:1.0:nameIdentifier in the error is throwing me off -- I've never encountered it before and while I did find some posts by others about this, I'm not quite sure what to do with the responses.

Can anyone perhaps provide some insight that might help me get this working?</div><div><br></div><div>Thanks!</div><div>Jason</div><div><div><br></div>-- <br><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><pre cols="72">Jason Rotunno
System & Security Administrator
Swarthmore College
500 College Ave
Swarthmore, PA 19081
610.328.8505<br></pre><pre cols="72"><b>VERIFY before you click!!</b>
  - Attackers make their emails look like they come from someone they don't.
  - Attackers make links look like they go to websites they don't.
  - Attackers disguise malware as receipts, invoices, faxes, etc.</pre><pre cols="72">Forward suspicious emails to <a href="mailto:phishing@swarthmore.edu" style="font-family:Arial,Helvetica,sans-serif" target="_blank">phishing@swarthmore.edu</a><span style="font-family:Arial,Helvetica,sans-serif">.</span></pre></div></div></div></div></div></div></div></div></div></div></div></div></div></div><div id="DAB4FAD8-2DD7-40BB-A1B8-4E2AA1F9FDF2"><br>
<table style="border-top:1px solid #d3d4de">
        <tr>
        <td style="width:55px;padding-top:13px"><a href="https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=webmail&utm_term=icon" target="_blank"><img src="https://ipmcdn.avast.com/images/icons/icon-envelope-tick-round-orange-animated-no-repeat-v1.gif" alt="" width="46" height="29" style="width: 46px; height: 29px;"></a></td>
                <td style="width:470px;padding-top:12px;color:#41424e;font-size:13px;font-family:Arial,Helvetica,sans-serif;line-height:18px">Virus-free. <a href="https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=webmail&utm_term=link" target="_blank" style="color:#4453ea">www.avast.com</a>
                </td>
        </tr>
</table><a href="#DAB4FAD8-2DD7-40BB-A1B8-4E2AA1F9FDF2" width="1" height="1"></a></div>