group memberships from two sources
David Bantz
dabantz at alaska.edu
Tue Mar 5 16:53:58 EST 2013
On Tue, 5 Mar 2013, at 11:53 , "Cantor, Scott" <cantor.2 at osu.edu> wrote:
> On 3/5/13 3:18 PM, "David Bantz" <dabantz at alaska.edu> wrote:
>
>> Is it appropriate to resolve and release the bare directory attributes
>> (as opposed to tidying them up in some way as suggested in
>> https://wiki.shibboleth.net/confluence/display/SHIB2/ResolverScriptAttribu
>> teDefinitionExamples)?
>
> What tidying is it suggesting?
Scripts on that page appear to build [ePA] attribute values from a piece of the group membership directory attribute;
so localizing, from the (real) AD memberOf value CN=SW_Employees,OU=Groups,OU=SW,DC=ua,DC=ad,DC=alaska,DC=edu
add the value SW_Employees to a local uakaffiliation attribute.
I would prefer not to do that and keep the SAML attributes directly reflecting the values in directories, but I can see service
owner preferring the shorter values.
>> Is it appropriate to keep these in separate attributes for release
>> (rather than combining them)?
>
> It seems like a questionable idea to me, but YMMV.
>
> ….All in all, it seems like a bad idea vs. just using isMemberOf or whatever
> is in eduPerson. For SAML purposes, why perpetuate all the weird history
> of group membership attributes vs. just picking one that exists and going
> with it?
As I indicated, that was a service owner request; it's a knowledgeable and reasonable
service owner for once, so that choice is presumably open to revision based on
good reasons.
Locally, people do strongly distinguish our Domain AD directory from the Oracle DSEE
and use them differently (let's not get into tribal warfare here) so it is not surprising to
me to have a service owner think of these as "different" as that reflects local practice.
Can you elaborate on why is seems questionable or a bad idea?
We will both (the service owner and I) appreciate your thoughts.
Thanks,
David
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130305/baf65873/attachment.html
More information about the users
mailing list