<html><body><div dir="ltr">SP’s metadata in my local cache, yes. And<span style="font-family:Calibri,sans-serif;font-size:11pt"> I’ve run these 3 variations:</span></div><div><p class="MsoNormal" style="margin:0cm;font-size:11pt;font-family:Calibri,sans-serif"></p></div><div><ul type="disc" style="margin-bottom:0cm"><li class="MsoNormal" style="margin:0cm;font-size:11pt;font-family:Calibri,sans-serif">all 4 policies</li><li class="MsoNormal" style="margin:0cm;font-size:11pt;font-family:Calibri,sans-serif">no policies</li><li class="MsoNormal" style="margin:0cm 0cm 12pt;font-size:11pt;font-family:Calibri,sans-serif">only the emalAddress policy</li></ul></div>
<div dir="ltr">With what seems to me the appropriate combination of configs:</div><div dir="ltr"><ul dir="ltr" style="margin:0px;list-style-type:"\002013   ""><li>no NameIDFormat elements in the SP metadata (all removed and verified by log message indicating metadata specifies “[]” format(s)]</li><li>saml-nameid generated from eduPersonPrincipalName with emalAddress format, triggered by this entityID</li><li>relying party override for this SP entityID to set nameIDFormatPrecendence to emailAddress</li></ul><div dir="ltr">the SAML Subject is the long opaque transient ID (with nameid-format:transient) - that is, not using ePPN, not in emailAddress format.</div><div dir="ltr"><br></div><div dir="ltr">If I remove the relying-party override for no very good reason other than desperate variation, then NO nameID at all is in the SAML Subject.</div><div dir="ltr"><span class="Apple-tab-span" style="white-space:pre">     </span></div><div dir="ltr">David</div></div><br>
<div class="gmail_quote">
    <div dir="ltr" class="gmail_attr">On 06Oct2022 at 16:36:03, "Wessel, Keith via users" <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>> wrote:<br></div>
    <blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex" type="cite">
        <div>
<div>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">

</div>
<div lang="EN-US" link="blue" vlink="purple" style="word-wrap:break-word">
<div class="WordSection1">
<p class="MsoNormal">Are you hosting this entity’s metadata yourself? If so, the obvious solution is to pull out the other name ID formats. Then, you won’t have to monkey with relying party overrides. If you aren’t hosting it yourself, I’d ask why not? If it’s
 not federation metadata, and if I can’t verify a signature on it (which one generally can’t unless it’s coming from someone who really has their act together), I live with the risks of having to manually update it and just download it and put it directly into
 my local metadata. Then, I can manipulate as needed.</p>
<p class="MsoNormal">Keith</p>
<p class="MsoNormal"> </p></div></div></div>
    </blockquote>
</div></body></html>