SAML2 attribute names breaking standards
Nate Klingenstein
ndk at internet2.edu
Fri Nov 22 10:54:15 EST 2013
Keith,
>I'm sure this breaks some accepted standards out there.
Yes, it does.
>Other than that, is there a technical reason I shouldn't do this?
If they're committed to this kind of attribute atrocity, then I'd at least ask them to do this in the "unspecified" attribute NameFormat rather than "URI" since it's pretty obviously not a URI.
Beyond that, it's just the typical issues of loose data definition and naming and the resultant complexity of your IdP's configuration files.
Thanks,
Nate.
More information about the users
mailing list