Multiple Attribute Encoders
Alex Olson
ako at byu.edu
Thu Dec 18 12:20:43 EST 2014
>
>It will end up in the assertion twice, one by each name. The above is
>inappropriate though, you're setting the name to a non-URI but not
>overriding the default nameFormat to something other than the "URI" SAML
>constant.
Ok, good to know, thank you very much
>
>
>Most SPs not following the standard are buggy throughout, so I imagine it
>will work, but it's still incorrect. If you have to use a made up name,
>set the encoder's nameFormat to
>"urn:oasis:names:tc:SAML:2.0:attrname-format:basic"
Understood.
>
>What you should do in any case is tell them to stop requiring a
>non-standard attribute name. Every IdP that tolerates it just perpetuates
>the problems. We all have to stand up. They're the vendor, we're the
>customer.
Will do. Since this last run of integrations with vendors, I’ve been
surprised at how many different attribute names I have to wrangle for them
to work. I feel like part of the power of SAML/Shibboleth is lost when,
with every integration, I have to define a whole new suite of attribute
definitions.
>
More information about the users
mailing list