Advice on planned IdP configuration changes associated with implementing SAML 2

Tom Scavo trscavo at gmail.com
Wed Sep 11 10:39:27 EDT 2013


On Wed, Sep 11, 2013 at 10:25 AM, Julian Williams
<julian.williams at it.ox.ac.uk> wrote:
>
> 1. That there is no need to include a SAML2 encoding for the old type of scoped eduPersonTargetedID (urn:mace:dir:attribute-def:eduPersonTargetedID).

That is correct. That URN is strictly a SAML1 construct. See the SAML
Attribute Profiles for details:

http://middleware.internet2.edu/dir/docs/internet2-mace-dir-saml-attributes-latest.pdf

> From what I have read it shouldn't be provided in a SAML2 request and SPs should be able to work without it provided they have the new type of eduPersonTargetedID. Or are there some instances where a 'legacy' SP/application might still have to get it?

If you send a SAML1 response to the SP, use the URN, but if you send a
SAML2 response, use the OID version of the attribute.

Tom


More information about the users mailing list