Follow-up on question that I recently asked on the users list about name ID support in Shibboleth IdP

Cantor, Scott cantor.2 at osu.edu
Tue Jan 31 15:12:58 GMT 2012


On 1/31/12 10:05 AM, "WULMS Alexander" <Alexander.WULMS at swift.com> wrote:
>
>I have meanwhile further read-up on the SAML documentation and have
>understood from the Oasis technical overview document that account
>linking can be performed using an authentication request with appropriate
>options in it, depending on the desired scenario (federation via
>persistent pseudonym identifiers, via transient pseudonym identifiers or
>via identity attributes).

That's about account linking at an SP that already has local accounts. If
your SP has local accounts, you can do this today. The IdP has essentially
nothing to do with it.

Any SP with local identities that adds SSO via a third party is
essentially doing account linking in one form or another.

The IdP does not currently act as an account store directly, or as a
relying party, and therefore has no particular notion of linking. There
are no plans to change that. Back end data stores containing account links
can be leveraged by the IdP just like any other data stores, to allow look
up of data based on multiple kinds of identifiers.

-- Scott



More information about the dev mailing list