<div dir="ltr">Keith,<div><br></div><div>We did an SSO setup with the National Student Clearinghouse recently (MyHub), and the NameID that you send doesn't show up anywhere as far as I can tell.  We send our opaque student ID.</div><div><br></div><div>Thanks,</div><div>Carl Waldbieser</div><div>ITS</div><div>Lafayette College</div></div><br><div class="gmail_quote gmail_quote_container"><div dir="ltr" class="gmail_attr">On Wed, Aug 13, 2025 at 2:48 PM Wessel, Keith via users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">Hi, all,<br>
<br>
It pained me to write that subject line.<br>
<br>
We're updating to a newer SSO integration with the National Student Clearinghouse. They tell me they need a persistent Name ID. That is, the name ID format needs to be set to urn:oasis:names:tc:SAML:2.0:nameid-format:persistent. But they also tell me that the value we send will be user-visible.<br>
<br>
While I'm tempted to say that we'll just send them the usual pairwise persistent ID that, while not pretty, at least works out of the box, I figured I'd at least explore doing what our registrar's office wanted.<br>
<br>
How would I get the IdP to use an attribute-sourced Name ID generator that sends an attribute as the Name ID but with a format of persistent?<br>
<br>
Thanks,<br>
Keith<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw" rel="noreferrer" target="_blank">https://shibboleth.atlassian.net/wiki/x/ZYEpPw</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>