PersistentId / principalName

Chad La Joie lajoie at itumi.biz
Wed Jul 4 19:19:35 EDT 2012


On Wed, Jul 4, 2012 at 5:25 AM, Ortner Nikolaus <N.Ortner at fh-kaernten.at> wrote:
> As I see it right I'd have to update the principalName of the database entries holding the persistentId - a) to migrate existing IDs when an user's principalName changes and b) to avoid confusion if there is a possibility that a principalName will later be assigned to another person's account.
> So am I expected to run into side-effects when updating records in this shibpid-table externally? (caching maybe?)

If you are changing people's organizational identifier than you will
also need to update the table.  The IdP has to be able to remap the
persistent ID back to the ID of the user that it belongs to so that it
can then proceed to further process requests like attribute queries.

> I propose the StoredIDDataConnector.getStoredId() should update the principalName in case it has changed (and the principalName is not used as the localId).
> And also some kind of error-handling when the IdP encounters a principalName resolving to two different active persistentId or a persistentId resolving to 2 different principalNames.

You can file a request in the issue tracker if you want.  I will state
now that I find the notion that the IdP should somehow guess that your
IDM has given an account a new unique key (and possibly reassigned the
old one) to be highly suspect.

-- 
Chad La Joie
www.itumi.biz
trusted identities, delivered


More information about the users mailing list