ADFS to Shibboleth

Mercer, Keith keith.mercer at ndus.edu
Thu Jan 2 17:02:30 EST 2014


Do you think that what I am doing is possible?  Is there a OID for employeeID?

-----Original Message-----
From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor, Scott
Sent: Thursday, January 2, 2014 4:00 PM
To: Shib Users
Subject: Re: ADFS to Shibboleth

On 1/2/14, 4:44 PM, "Mercer, Keith" <keith.mercer at ndus.edu> wrote:

>I thought could change query= to employeeID but that didn¹t see to work.
>I am thinking I would need to do something with the iod¹s also.  Any 
>assistance would be helpful.

The OID is the name of the attribute when using the SAML profile for LDAP attributes properly. It's just a URI string in the rule, and that's the correct URI for employeeNumber.

The rest is up to ADFS. I didn't find it to be very usable when it comes to debugging attribute behavior with those undocumented scripting rules, at least when it was first released.

-- Scott


--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list