IDP-initiaded SSO or IdPUnsolicitedSSO

Jehan Procaccia Jehan.Procaccia at it-sudparis.eu
Thu Oct 17 16:41:44 EDT 2013


Le 17/10/2013 22:31, Cantor, Scott a écrit :
> On 10/17/13 4:25 PM, "Jehan Procaccia" <Jehan.Procaccia at it-sudparis.eu>
> wrote:
>
>> following your recommendations, I created a custom NameID for that
>> vendor,
>> but I still cannot figure out how to use a "precedence capability" to
>> ensure that for that vendor, it is that custom NameID that is released
> I don't believe you can (and would not in general think you should be able
> to) set precedence based on "unspecified".
>
> If you must use that (which is silly), you can probably only control that
> by explicit control over attribute release to prevent more than one
> possible candidate from being considered.
>
> -- Scott
>
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
oops, that was a silly cut&paste from the wiki sample/template
would it be more accurate to set precedence for that new custom NameID 
based on that definition ?

<resolver:AttributeDefinition id="*travelId*" xsi:type="Simple" 
sourceAttributeID="mail"
xmlns="urn:mace:shibboleth:2.0:resolver:ad"><resolver:Dependency 
ref="ldapTMSP" />
     <resolver:AttributeEncoder xsi:type="SAML1StringNameIdentifier"
     xmlns="urn:mace:shibboleth:2.0:attribute:encoder" 
nameFormat="*urn:mace:shibboleth:1.0:nameIdentifier*" />
     <resolver:AttributeEncoder xsi:type="SAML2StringNameID"
     xmlns="urn:mace:shibboleth:2.0:attribute:encoder" 
nameFormat="*urn:oasis:names:tc:SAML:2.0:nameid-format:transient*" />
</resolver:AttributeDefinition>

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20131017/eda68cce/attachment.html 


More information about the users mailing list