<!DOCTYPE html>
<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=UTF-8">
</head>
<body text="#000000" bgcolor="#FFFFFF">
<p><font face="Calibri">Hello,</font></p>
<p><font face="Calibri">I'm reviewing deprecation warnings before
the upgrade of a Shibboleth IDP v4.3.3 to version 5 and I'm
confused about this one:</font></p>
<p><font face="Courier New, Courier, monospace" size="2"
color="#0080ff">WARN [DEPRECATED:128] - xsi:type 'SAML2NameID',
(file [conf/attribute-resolver.xml]): This will be removed in
the next major version of this software; replacement is (none)</font></p>
<p><font face="Calibri">Indeed, I've got such a declaration in the
attribute resolver:</font></p>
<div
style="color: #cccccc;background-color: #1f1f1f;font-family: Consolas, 'Courier New', monospace;font-weight: normal;font-size: 14px;line-height: 19px;white-space: pre;"><div><span
style="color: #cccccc;"> </span><span style="color: #808080;"><</span><span
style="color: #569cd6;">AttributeDefinition</span><span
style="color: #cccccc;"> </span><span style="color: #9cdcfe;">xsi:type</span><span
style="color: #cccccc;">=</span><span style="color: #ce9178;">"SAML2NameID"</span><span
style="color: #cccccc;"> </span><span style="color: #9cdcfe;">id</span><span
style="color: #cccccc;">=</span><span style="color: #ce9178;">"eduPersonTargetedID"</span></div><div><span
style="color: #cccccc;"> </span><span
style="color: #9cdcfe;">nameIdFormat</span><span
style="color: #cccccc;">=</span><span style="color: #ce9178;">"urn:oasis:names:tc:SAML:2.0:nameid-format:persistent"</span><span
style="color: #cccccc;"> </span><span style="color: #808080;">></span></div><div><span
style="color: #cccccc;"> </span><span style="color: #808080;"><</span><span
style="color: #569cd6;">InputDataConnector</span><span
style="color: #cccccc;"> </span><span style="color: #9cdcfe;">ref</span><span
style="color: #cccccc;">=</span><span style="color: #ce9178;">"computedID"</span><span
style="color: #cccccc;"> </span><span style="color: #9cdcfe;">attributeNames</span><span
style="color: #cccccc;">=</span><span style="color: #ce9178;">"computedID"</span><span
style="color: #cccccc;"> </span><span style="color: #808080;">/></span></div><div><span
style="color: #cccccc;"> </span><span style="color: #808080;"><</span><span
style="color: #569cd6;">AttributeEncoder</span><span
style="color: #cccccc;"> </span><span style="color: #9cdcfe;">xsi:type</span><span
style="color: #cccccc;">=</span><span style="color: #ce9178;">"SAML1XMLObject"</span><span
style="color: #cccccc;"> </span><span style="color: #9cdcfe;">name</span><span
style="color: #cccccc;">=</span><span style="color: #ce9178;">"urn:oid:1.3.6.1.4.1.5923.1.1.1.10"</span><span
style="color: #cccccc;"> </span><span style="color: #808080;">/></span></div><div><span
style="color: #cccccc;"> </span><span style="color: #808080;"><</span><span
style="color: #569cd6;">AttributeEncoder</span><span
style="color: #cccccc;"> </span><span style="color: #9cdcfe;">xsi:type</span><span
style="color: #cccccc;">=</span><span style="color: #ce9178;">"SAML2XMLObject"</span><span
style="color: #cccccc;"> </span><span style="color: #9cdcfe;">name</span><span
style="color: #cccccc;">=</span><span style="color: #ce9178;">"urn:oid:1.3.6.1.4.1.5923.1.1.1.10"</span><span
style="color: #cccccc;"> </span><span style="color: #9cdcfe;">friendlyName</span><span
style="color: #cccccc;">=</span><span style="color: #ce9178;">"eduPersonTargetedID"</span><span
style="color: #cccccc;"> </span><span style="color: #808080;">/></span></div><div><span
style="color: #cccccc;"> </span><span style="color: #808080;"></</span><span
style="color: #569cd6;">AttributeDefinition</span><span
style="color: #808080;">></span></div></div>
<p><font face="Calibri">But according to Atlassian documentation, I
beleive that I could ignore it :</font></p>
<p><i><font face="Calibri">"</font><span
style="color: rgb(41, 42, 46); font-family: "Atlassian Sans", ui-sans-serif, -apple-system, BlinkMacSystemFont, "Segoe UI", Ubuntu, "Helvetica Neue", sans-serif; font-size: 16px; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; text-align: left; text-indent: 0px; text-transform: none; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: pre-wrap; background-color: rgb(255, 255, 255); text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial; display: inline !important; float: none;">In fact they were not, and their use (while still unsupported and undocumented) will produce a less aggressive “at risk” warning going forward. There are no explicit plans to remove them, but their use is incompatible with the vast majority of SAML software and should not be used in new deployments."</span></i></p>
<p><font face="Calibri">Source: <a moz-do-not-send="true"
href="https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199500925/Upgrading"
class="moz-txt-link-freetext">https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199500925/Upgrading</a></font></p>
<p><font face="Calibri">However I've had a deeper look and, if I
understood properly, I should not rely on such identifiers:</font></p>
<p><i><span
style="color: rgb(41, 42, 46); font-family: "Atlassian Sans", ui-sans-serif, -apple-system, BlinkMacSystemFont, "Segoe UI", Ubuntu, "Helvetica Neue", sans-serif; font-size: 16px; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: pre-wrap; background-color: rgb(255, 255, 255); text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial; display: inline !important; float: none;">"You should consider carefully whether this kind of identifier meets your needs. They can be difficult to deal with, they work very poorly with a wide variety of applications, and they are often more trouble than they're worth. Be cautious, and don't commit to supporting something you don't want to have to support."</span></i></p>
<p><font face="Calibri">Source: <a moz-do-not-send="true"
href="https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199507892/PersistentNameIDGenerationConfiguration"
class="moz-txt-link-freetext">https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199507892/PersistentNameIDGenerationConfiguration</a></font></p>
<p><font face="Calibri">But still digging, I've found that I could
declare that attribute in another location: </font><font
face="Courier New, Courier, monospace" size="2" color="#0080ff">dist/conf/saml-nameid.xml</font></p>
<div
style="color: #cccccc;background-color: #1f1f1f;font-family: Consolas, 'Courier New', monospace;font-weight: normal;font-size: 14px;line-height: 19px;white-space: pre;"><div><span
style="color: #cccccc;"> </span><span style="color: #6a9955;"><!-- SAML 2 NameID Generation --></span></div><div><span
style="color: #cccccc;"> </span><span style="color: #808080;"><</span><span
style="color: #569cd6;">util:list</span><span
style="color: #cccccc;"> </span><span style="color: #9cdcfe;">id</span><span
style="color: #cccccc;">=</span><span style="color: #ce9178;">"shibboleth.SAML2NameIDGenerators"</span><span
style="color: #808080;">></span></div><div><span
style="color: #cccccc;"> </span></div><div><span
style="color: #cccccc;"> </span><span style="color: #808080;"><</span><span
style="color: #569cd6;">ref</span><span style="color: #cccccc;"> </span><span
style="color: #9cdcfe;">bean</span><span style="color: #cccccc;">=</span><span
style="color: #ce9178;">"shibboleth.SAML2TransientGenerator"</span><span
style="color: #cccccc;"> </span><span style="color: #808080;">/></span></div><div><span
style="color: #cccccc;"> </span></div><div><span
style="color: #cccccc;"> </span><span style="color: #6a9955;"><!-- Uncommenting this bean requires configuration in saml-nameid.properties. --></span></div><div><span
style="color: #cccccc;"> </span><span style="color: #6a9955;"><!--</span></div><div><span
style="color: #6a9955;"> <ref bean="shibboleth.SAML2PersistentGenerator" /></span></div><div><span
style="color: #6a9955;"> --></span></div>
<div><span style="color: #cccccc;"> </span><span
style="color: #6a9955;"><!--</span></div><div><span
style="color: #6a9955;"> <bean parent="shibboleth.SAML2AttributeSourcedGenerator"</span></div><div><span
style="color: #6a9955;"> p:omitQualifiers="true"</span></div><div><span
style="color: #6a9955;"> p:format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress"</span></div><div><span
style="color: #6a9955;"> p:attributeSourceIds="#{ {'mail'} }" /></span></div><div><span
style="color: #6a9955;"> --></span></div><div><span
style="color: #cccccc;"> </span></div><div><span
style="color: #cccccc;"> </span><span style="color: #808080;"></</span><span
style="color: #569cd6;">util:list</span><span
style="color: #808080;">></span></div></div>
<p><font face="Calibri">So, at the end I'm a bit lost and I don't
know what is the best to do. Shall I ignore the deprecation
warning ? Shall I replace the persistent attribute by another
one ? Shall I move to saml-nameid.xml ?</font></p>
<p><font face="Calibri">Because the upgrade is in-place, I fear to
break something and would need some advices.</font></p>
<p><font face="Calibri">Thank you</font></p>
<p><font face="Calibri">Best regards,</font></p>
<p><font face="Calibri">Julien</font></p>
<p><font face="Calibri"><br>
</font></p>
<p><font face="Calibri"><br>
</font></p>
<p><font face="Calibri"><br>
</font></p>
</body>
</html>