IdPv3 direct NameID mapping default

Scott Koranda skoranda at gmail.com
Tue Sep 8 09:52:55 EDT 2015


> On 9/8/15, 9:43 AM, "dev on behalf of Scott Koranda" <dev-bounces at shibboleth.net on behalf of skoranda at gmail.com> wrote:
> 
> >The default for IdPv3 for direct NameID mapping as recorded in
> >subject-c14n.xml in the shibboleth.NameTransformPredicate is
> >an empty whitelist--no relying parties by default can complete
> >an attribute query with a direct NameID mapping.
> >
> >I am curious why that is the default?
> 
> Mainly because my assumption was that people would expect to limit it and not support it for every SP, so I left it there as a placeholder for filling in the exception cases they might want to allow.
> 
> We've never had that kind of default configuration before so I didn't have anything to go on beyond that.
> 

Thanks. I configured an IdPv3 as an attribute authority (only)
and ran into that configuration default and was just curious.

Cheers,

Scott K


More information about the dev mailing list