PersistentId / principalName
Chad La Joie
lajoie at itumi.biz
Wed Jul 4 19:13:47 EDT 2012
On Wed, Jul 4, 2012 at 7:08 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> PersistentIDs are (and in fact MUST be) totally divorced from any
> name-based identifier for a user. If something breaks when a username
> changes, your deployment needs to be adjusted. I can't imagine that the
> connector in question has any issue with this.
Well, they can't be totally divorced from each other within the IdP
because the IdP has to be able to reverse a PID in to the
organization-local ID. That said, the IdP does *not* require that
that ID be used as an input to the algorithm that generates of the
PID.
--
Chad La Joie
www.itumi.biz
trusted identities, delivered
More information about the users
mailing list