duplicate attribute value issue in idp 2.3.3
Chad La Joie
lajoie at itumi.biz
Tue Aug 2 17:42:26 BST 2011
On Tue, Aug 2, 2011 at 12:35, Cantor, Scott E. <cantor.2 at osu.edu> wrote:
> The advice we give in general is to use the Subject to carry the NameID
> with SAML 2.0, which in this particular case isn't subject to the bug,
> that's all I meant.
Yes, encoding the persistent identifier in to the Subject also avoids
this issue. I personally wish people always carried "the" identifier
for the user in the Subject, but many folks don't.
>> The correct format is based on XMLObjects (and the only
>>attribute that is based on XMLObjects unless there are IdP extensions
>>that creates XMLObject values) and so is affected by this.
>
> The correct format is, but a quirk of the IdP is that if you want it in
> the Subject, you have to attach a String-based encoder to the attribute
> definition, so that's a way around it for SAML 2.0 at least. No help with
> SAML 1.1, so I'll shut up about it.
Yeah, the data in question here is confusing because it's the only bit
of data we have that has two different formats when encoded as an
attribute and may also be encoded as a Subject NameID. See above
comment...
--
Chad La Joie
www.itumi.biz
trusted identities, delivered
More information about the users
mailing list