<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Hi Scott,</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
So <a href="https://play01982.soton.ac.uk/shibboleth" id="LPlnk836283">https://play01982.soton.ac.uk/shibboleth</a> is the entityID of a test SP. Swapping out the upgraded IDP for a non-upgraded IDP and it works fine, no InvalidNameIDPolicy error. So something
 I have missed in the Release notes that causes this perhaps? Any tips to diagnose, perhaps put into debug?<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Thanks<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div id="appendonsend"></div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> Cantor, Scott <cantor.2@osu.edu><br>
<b>Sent:</b> 21 June 2022 13:02<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Cc:</b> Nilan Morjaria-Patel <N.Morjaria-Patel@soton.ac.uk><br>
<b>Subject:</b> Re: Upgrade from v4.0.1 to v4.2.1 - InvalidNameIDPolicy</font>
<div> </div>
</div>
<div class="BodyFragment"><font size="2"><span style="font-size:11pt;">
<div class="PlainText">CAUTION: This e-mail originated outside the University of Southampton.<br>
<br>
On 6/20/22, 10:08 AM, "users on behalf of Nilan Morjaria-Patel via users" <users-bounces@shibboleth.net on behalf of users@shibboleth.net> wrote:<br>
<br>
>    As stated in the subject I have just attempted to upgrade one of our dev Shibb IDP servers, however I now<br>
> get the following in idp-warn.log:<br>
<br>
There's nothing about an upgrade that suddenly makes a NameIDPolicy show up. That's the SP's choice.<br>
<br>
>    It appears the SP is requesting urn:oasis:names:tc:SAML:2.0:nameid-format:transient.<br>
<br>
It doesn't appear that way at all, it's requesting persistent.<br>
<br>
-- Scott<br>
<br>
<br>
</div>
</span></font></div>
</body>
</html>