IdPv3 direct NameID mapping default
Scott Koranda
skoranda at gmail.com
Tue Sep 8 09:52:55 EDT 2015
> On 9/8/15, 9:43 AM, "dev on behalf of Scott Koranda" <dev-bounces at shibboleth.net on behalf of skoranda at gmail.com> wrote:
>
> >The default for IdPv3 for direct NameID mapping as recorded in
> >subject-c14n.xml in the shibboleth.NameTransformPredicate is
> >an empty whitelist--no relying parties by default can complete
> >an attribute query with a direct NameID mapping.
> >
> >I am curious why that is the default?
>
> Mainly because my assumption was that people would expect to limit it and not support it for every SP, so I left it there as a placeholder for filling in the exception cases they might want to allow.
>
> We've never had that kind of default configuration before so I didn't have anything to go on beyond that.
>
Thanks. I configured an IdPv3 as an attribute authority (only)
and ran into that configuration default and was just curious.
Cheers,
Scott K
More information about the dev
mailing list