[security-dev] question about setting NameIDPolicy format