<div dir="ltr"><div>I can't speak for others as to why folks don't use a metadata-centric approach, but for myself, this use of the metadata filter was completely novel to me until I saw this response.</div><div><br></div><div>While the documentation may not suggest using generator beans and activation conditions (or other non-metadata alternatives), it also, at least as far as I've encountered, does not obviously point you to a metadata filter as a best practice for these sorts of situations. Those of us responsible for making it work do our best with the information we can find.</div><div><br></div><div>The way we accommodated this sort of nameid format issue was to use a RelyingPartyOverride with a nameIDFormatPrecedence – but now that we're aware of the metadata filter approach and its recommendation as a preferred practice, we can explore it. I'm pleased to have learned of it.</div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Fri, Jun 3, 2022 at 8:04 AM Cantor, Scott via users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-style:solid;border-left-color:rgb(204,204,204);padding-left:1ex">You don't do this by touching anything but metadata. Add the relevant NameIDFormat to the SP's metadata or add a filter to add it. Done.<br>
<br>
Do NOT create one-off NameID generator beans and do not use activation conditions to control them. Just because it's possible doesn't mean you should ever do it. It's there as an absolute last resort.<br>
<br>
The documentation does not in any way suggest doing this, so I don't know why people are doing it or what would lead somebody to think it makes sense, but it's analagous to creating an LDAP plugin that changes what attribute values are served up for a fixed attribute type based on the bind DN. Nobody would even think of doing that, and this is the same.<br>
<br>
If you create an email Format generator based on the filtered value of mail (or whatever attribute you use), then you need not worry about anything but releasing the relevant attribute to the SP and making sure its metadata stipulates the right Format.<br>
<br>
-- Scott<br>
<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw" rel="noreferrer" target="_blank">https://shibboleth.atlassian.net/wiki/x/ZYEpPw</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div><div><br></div>-- <br><div dir="ltr" class="gmail_signature"><div dir="ltr"><font face="arial, sans-serif">Baron Fujimoto <<a href="mailto:baron@hawaii.edu" target="_blank">baron@hawaii.edu</a>> ::: UH Information Technology Services<br>minutas cantorum, minutas balorum, minutas carboratum descendus pantorum</font></div></div></div>