IDP-initiaded SSO or IdPUnsolicitedSSO
Jehan Procaccia
Jehan.Procaccia at it-sudparis.eu
Thu Oct 17 16:41:44 EDT 2013
Le 17/10/2013 22:31, Cantor, Scott a écrit :
> On 10/17/13 4:25 PM, "Jehan Procaccia" <Jehan.Procaccia at it-sudparis.eu>
> wrote:
>
>> following your recommendations, I created a custom NameID for that
>> vendor,
>> but I still cannot figure out how to use a "precedence capability" to
>> ensure that for that vendor, it is that custom NameID that is released
> I don't believe you can (and would not in general think you should be able
> to) set precedence based on "unspecified".
>
> If you must use that (which is silly), you can probably only control that
> by explicit control over attribute release to prevent more than one
> possible candidate from being considered.
>
> -- Scott
>
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
oops, that was a silly cut&paste from the wiki sample/template
would it be more accurate to set precedence for that new custom NameID
based on that definition ?
<resolver:AttributeDefinition id="*travelId*" xsi:type="Simple"
sourceAttributeID="mail"
xmlns="urn:mace:shibboleth:2.0:resolver:ad"><resolver:Dependency
ref="ldapTMSP" />
<resolver:AttributeEncoder xsi:type="SAML1StringNameIdentifier"
xmlns="urn:mace:shibboleth:2.0:attribute:encoder"
nameFormat="*urn:mace:shibboleth:1.0:nameIdentifier*" />
<resolver:AttributeEncoder xsi:type="SAML2StringNameID"
xmlns="urn:mace:shibboleth:2.0:attribute:encoder"
nameFormat="*urn:oasis:names:tc:SAML:2.0:nameid-format:transient*" />
</resolver:AttributeDefinition>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20131017/eda68cce/attachment.html
More information about the users
mailing list