Multiple Attribute Encoders

Alex Olson ako at byu.edu
Thu Dec 18 12:20:43 EST 2014


>
>It will end up in the assertion twice, one by each name. The above is 
>inappropriate though, you're setting the name to a non-URI but not 
>overriding the default nameFormat to something other than the "URI" SAML 
>constant.

Ok, good to know, thank you very much
>
>
>Most SPs not following the standard are buggy throughout, so I imagine it 
>will work, but it's still incorrect. If you have to use a made up name, 
>set the encoder's nameFormat to
>"urn:oasis:names:tc:SAML:2.0:attrname-format:basic"
Understood.
>
>What you should do in any case is tell them to stop requiring a 
>non-standard attribute name. Every IdP that tolerates it just perpetuates 
>the problems. We all have to stand up. They're the vendor, we're the 
>customer.
Will do. Since this last run of integrations with vendors, I’ve been 
surprised at how many different attribute names I have to wrangle for them 
to work. I feel like part of the power of SAML/Shibboleth is lost when, 
with every integration, I have to define a whole new suite of attribute 
definitions.
>


More information about the users mailing list