on eduPersonTargetedID (ePTID) and SAML interoperability

Cantor, Scott cantor.2 at osu.edu
Wed Apr 24 09:54:55 EDT 2013


On 4/24/13 4:20 AM, "Roberto Benedetti" <r.benedetti at cineca.it> wrote:

>I think I know how to do that on the Shibboleth IdP.
>are you saying it can be also done on the OpenSSO IdP?

I was talking about Shibboleth.

>I am at the SP side and all other Shib and SimpleSAML IdPs work as
>expected. we'd prefer not making changes on a production properly
>working service...   -who would?

I think the point of middleware is to perform these translations and
accomodations. That's the whole point of the Shibboleth design, to
insulate applications.

>http://middleware.internet2.edu/dir/docs/internet2-mace-dir-saml-attribute
>s-200804.pdf,
>sections 2.3.2.1.x.
>the Shibboleth IdP *reflects* the "newer, recommended name and value
>syntax" shown in section 2.5.

Yes, but that wasn't the comparison you were making with OpenSSO. There is
no difference semantically between a NameID and that attribute.

-- Scott




More information about the users mailing list