如何解密NameID值并通过NameID获取testuid?SimpleSAMLphp技术咨询
testuid) Instead of Encrypted/Hash Value Alright, let's walk through this step by step. First, let's unpack your configuration to understand why you're getting an "encrypted" value right now:
Your IDP's authproc.idp config sets up three NameID generators in sequence:
saml:TransientNameID: Creates a one-time, temporary NameIDsaml:PersistentNameID: Generates a hashed persistent NameID using theeduPersonPrincipalNameattribute (this is almost certainly the "encrypted" value you're seeing—persistent NameIDs are hashed, not encrypted, and the hash is irreversible)saml:AttributeNameID: Uses themailattribute directly as a NameID (in email format)
Plus, your user store (example-userpass) maps testuid:testtest to the uid attribute with value ['testuid'].
Here are two straightforward ways to get the plaintext testuid you need:
Option 1: Grab the uid Directly from Attributes (Easiest!)
Since you're already fetching attributes with $attrs = $as->getAttributes();, you don't even need to mess with the NameID. The testuid value is already in the uid attribute. Just access it directly:
require_once("pathlin"); $as = new SimpleSAML_Auth_Simple('default-sp'); $attrs = $as->getAttributes(); // Fetch the testuid value if (isset($attrs['uid']) && !empty($attrs['uid'])) { $testuid = $attrs['uid'][0]; // Attributes are arrays, so grab the first element echo $testuid; // Will output "testuid" for your test user }
This is the most direct approach because the uid attribute is already being returned to your SP.
Option 2: Adjust IDP to Return uid as Plaintext NameID
If you specifically need the NameID itself to be testuid, modify your IDP's authproc.idp config to prioritize a NameID generator that uses the uid attribute. Add a saml:AttributeNameID entry at the top of the authproc list (higher numbers run later, so lower numbers take priority):
'authproc.idp' => [ // Add this to use uid as NameID first 1 => array( 'class' => 'saml:AttributeNameID', 'attribute' => 'uid', 'Format' => 'urn:oasis:names:tc:SAML:2.0:nameid-format:persistent', // Or your preferred format ), // Keep existing configs if needed 2 => array( 'class' => 'saml:TransientNameID', ), 3 => array( 'class' => 'saml:PersistentNameID', 'attribute' => 'eduPersonPrincipalName', ), 4 => array( 'class' => 'saml:AttributeNameID', 'attribute' => 'mail', 'Format' => 'urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress', ), ],
After this change, when you call $as->getAuthData("saml:sp:NameID")->value, you'll get the plaintext testuid instead of the hashed value.
Key Notes to Keep in Mind
- The "encrypted" value you're seeing is likely a hash from the
PersistentNameIDprocessor, not actual encryption. Hashes can't be reversed to get the originaltestuidvalue, so you can't decode it directly—you need to adjust how the NameID is generated instead. - Your current
PersistentNameIDconfig useseduPersonPrincipalName, but your test user doesn't have this attribute defined. SimpleSAMLphp might fall back to usinguidto generate the hash, but again, that hash is irreversible. - If your SP requests a specific NameID format (e.g., email format), the IDP will use the matching generator from your authproc list. Make sure the format you want is prioritized if you go with Option 2.
内容的提问来源于stack exchange,提问作者Antoine Soffray

