Skip to Content.
Sympa Menu

shibboleth-dev - RE: [Shib-Dev] invalid InvalidNameIDPolicy

Subject: Shibboleth Developers

List archive

RE: [Shib-Dev] invalid InvalidNameIDPolicy


Chronological Thread 
  • From: "Scott Cantor" <>
  • To: <>
  • Subject: RE: [Shib-Dev] invalid InvalidNameIDPolicy
  • Date: Fri, 6 Aug 2010 15:08:48 -0400
  • Organization: The Ohio State University

> I get a saml2 authn request without a nameid element. The idp always
> immediately rejects this with an InvalidNameIDPolicy error.

That's a pretty big bug, good catch.

> Maybe most SPs, like shib's does, always send a nameidpolicy element.

The only reason we tend to send it is the stupid AllowCreate nonsense, yet
another Liberty wart. It's quite common not to.

-- Scott





Archive powered by MHonArc 2.6.16.

Top of Page