<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:"Trebuchet MS";
        panose-1:2 11 6 3 2 2 2 2 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        font-size:10.0pt;
        font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
span.EmailStyle19
        {mso-style-type:personal-reply;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple" style="word-wrap:break-word">
<div class="WordSection1">
<p class="MsoNormal"><span style="font-size:11.0pt">Les,<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">My suspicion is that your main RP override is too broad and is applying to everything. And when you comment out your RP override for this one SP, it's defaulting to the broad override which is forcing "persistent
 OR transient".<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">Instead of completely commenting out the RP override, making an RP override for this one SP but excluding any NameIDFormatPreferences. Set it up for the same SAML2.SSO profile and see if that works.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">- Steve<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
<div style="border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal" style="margin-bottom:12.0pt"><b><span style="font-size:12.0pt;color:black">From:
</span></b><span style="font-size:12.0pt;color:black">users <users-bounces@shibboleth.net> on behalf of Les LaCroix via users <users@shibboleth.net><br>
<b>Date: </b>Thursday, August 4, 2022 at 8:11 PM<br>
<b>To: </b>Shib Users <users@shibboleth.net><br>
<b>Cc: </b>Les LaCroix <llacroix@carleton.edu><br>
<b>Subject: </b>Re: custom nameid formats and metadata-driven config<o:p></o:p></span></p>
</div>
<div>
<div>
<div>
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:"Trebuchet MS",sans-serif;color:#073763">There is no NameIDPolicy in the SAML requests from this service.  The vendor-generated metadata file doesn't contain any NameIDFormat, but it's not expected
 to work out of the box either, as it doesn't include an entityID.  They don't care what the nameid-format specifier is.  They just need the user's username returned as the saml2:Subject.<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:"Trebuchet MS",sans-serif;color:#073763"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:"Trebuchet MS",sans-serif;color:#073763">I added "<md:NameIDFormat>urn:oid:0.9.2342.19200300.100.1.1</md:NameIDFormat>" in the SP's metadata, but my understanding now is that alone is insufficient
 because of the nameIDFormatPrecedence that we added to our default relying party configuration years ago.<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:"Trebuchet MS",sans-serif;color:#073763"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:"Trebuchet MS",sans-serif;color:#073763">Based on <a href="https://urldefense.com/v3/__https:/shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1265631679/MetadataDrivenConfiguration*NameID-Format-Selection__;Iw!!IBzWLUs!Unp0jKZhTHptY1vdPiIAVBZ7iAet21f55_lu76YRKcAfmtWRUsi7w_G3ZSkfnmat47YVTP6igCqgq0t1$">https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1265631679/MetadataDrivenConfiguration#NameID-Format-Selection</a>,
 I thought that adding the following to the metadata would trigger the custom format.  It does not.<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:"Trebuchet MS",sans-serif;color:#073763"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:"Trebuchet MS",sans-serif;color:#073763">      <mdattr:EntityAttributes><br>
         <saml:Attribute Name="<a href="https://urldefense.com/v3/__http:/shibboleth.net/ns/profiles/nameIDFormatPrecedence__;!!IBzWLUs!Unp0jKZhTHptY1vdPiIAVBZ7iAet21f55_lu76YRKcAfmtWRUsi7w_G3ZSkfnmat47YVTP6igFD-mvyj$">http://shibboleth.net/ns/profiles/nameIDFormatPrecedence</a>"<br>
               NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><br>
            <saml:AttributeValue>urn:oid:0.9.2342.19200300.100.1.1</saml:AttributeValue><br>
         </saml:Attribute>        <br>
      </mdattr:EntityAttributes><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:"Trebuchet MS",sans-serif;color:#073763"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:"Trebuchet MS",sans-serif;color:#073763">I do, however, trigger the custom format if I instead add the following to my relying-party.xml.<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:"Trebuchet MS",sans-serif;color:#073763"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:"Trebuchet MS",sans-serif;color:#073763">        <bean parent="RelyingPartyByName"<br>
                    c:relyingPartyIds="#{{'<a href="https://urldefense.com/v3/__http:/sp.example.org/'*7D__;JQ!!IBzWLUs!Unp0jKZhTHptY1vdPiIAVBZ7iAet21f55_lu76YRKcAfmtWRUsi7w_G3ZSkfnmat47YVTP6igN9vEiSH$">http://sp.example.org/'}</a>}"><br>
            <property name="profileConfigurations"><br>
                <list><br>
                    <bean parent="SAML2.SSO.MDDriven"<br>
                            p:nameIDFormatPrecedence="#{{'urn:oid:0.9.2342.19200300.100.1.1'}}" /><br>
                </list><br>
            </property><br>
        </bean><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:"Trebuchet MS",sans-serif;color:#073763"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:"Trebuchet MS",sans-serif;color:#073763">I am using an entity attribute for this SP to set encryptAssertions=false (not shown above), and I'm really hoping to figure out how to also override nameIDFormatPrecedence
 with an entity attribute too.<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:"Trebuchet MS",sans-serif;color:#073763"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:"Trebuchet MS",sans-serif;color:#073763">Thanks, -Les<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:12.0pt;font-family:"Trebuchet MS",sans-serif;color:#073763"><o:p> </o:p></span></p>
</div>
<div>
<div>
<div>
<div>
<p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
</div>
<div>
<table class="MsoNormalTable" border="0" cellspacing="0" cellpadding="0" style="border-collapse:collapse">
<tbody>
<tr>
<td style="border:none;border-right:solid #CCCCCC 1.0pt;padding:5.0pt 5.0pt 5.0pt 5.0pt;overflow:hidden">
<p style="margin:0in"><span style="color:#888888"><a href="https://urldefense.com/v3/__http:/www.carleton.edu/__;!!IBzWLUs!Unp0jKZhTHptY1vdPiIAVBZ7iAet21f55_lu76YRKcAfmtWRUsi7w_G3ZSkfnmat47YVTP6igKQYuPko$" target="_blank"><span style="color:#888888;text-decoration:none"><span style="font-family:"Arial",sans-serif;color:#1155CC;border:none windowtext 1.0pt;padding:0in"><img border="0" width="70" height="73" style="width:.7291in;height:.7604in" id="_x0000_i1025" src="https://lh6.googleusercontent.com/QEL1To3Ci_dJA1huaKzfZ0Lf4MaZlAy_f-W3vQjbyzNq_yXq_ZYGv3tuT4dkaZS_bZ5X6fZR4iKzBboZhxbCF5htZFnLNKGqmrzHsVJtsjsy0pfK5w2z0Dlq-EtZcWhv0PxBpWmR"></span></span></a><o:p></o:p></span></p>
</td>
<td valign="top" style="border:none;padding:.15in .15in .15in .15in;overflow:hidden">
<p style="margin:0in"><b><span style="font-family:"Arial",sans-serif;color:#DEA410">Les LaCroix '79</span></b><span style="color:#888888"><o:p></o:p></span></p>
<p style="margin:0in"><span style="font-family:"Arial",sans-serif;color:#0B5091">Strategic Technologist</span><span style="color:#888888"><o:p></o:p></span></p>
<p style="margin:0in"><span style="font-family:"Arial",sans-serif;color:#0B5091">Information Technology Services</span><span style="color:#888888"><o:p></o:p></span></p>
<p style="margin:0in"><span style="font-family:"Arial",sans-serif;color:#0B5091">t: (507) 222-5455</span><span style="color:#888888"><o:p></o:p></span></p>
</td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
<p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
</div>
<p class="MsoNormal"><span style="font-size:11.0pt"><o:p> </o:p></span></p>
<div>
<div>
<p class="MsoNormal"><span style="font-size:11.0pt">On Thu, Aug 4, 2022 at 9:05 AM Mak, Steven <<a href="mailto:makst@upenn.edu" target="_blank">makst@upenn.edu</a>> wrote:<o:p></o:p></span></p>
</div>
<blockquote style="border:none;border-left:solid #CCCCCC 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in">
<div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span style="font-size:11.0pt">Les,<o:p></o:p></span></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span style="font-size:11.0pt"> <o:p></o:p></span></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span style="font-size:11.0pt">What is the service sending for a NameIDPolicy in the SAML request? If they're sending something that is not what their devs have stated they want
 (which is often the case), that could explain why the SP metadata route didn't work.<o:p></o:p></span></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span style="font-size:11.0pt"> <o:p></o:p></span></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span style="font-size:11.0pt">- Steve
<o:p></o:p></span></p>
</div>
</div>
</blockquote>
</div>
</div>
</div>
</body>
</html>