ADFS to Shibboleth
Mercer, Keith
keith.mercer at ndus.edu
Thu Jan 2 17:02:30 EST 2014
Do you think that what I am doing is possible? Is there a OID for employeeID?
-----Original Message-----
From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor, Scott
Sent: Thursday, January 2, 2014 4:00 PM
To: Shib Users
Subject: Re: ADFS to Shibboleth
On 1/2/14, 4:44 PM, "Mercer, Keith" <keith.mercer at ndus.edu> wrote:
>I thought could change query= to employeeID but that didn¹t see to work.
>I am thinking I would need to do something with the iod¹s also. Any
>assistance would be helpful.
The OID is the name of the attribute when using the SAML profile for LDAP attributes properly. It's just a URI string in the rule, and that's the correct URI for employeeNumber.
The rest is up to ADFS. I didn't find it to be very usable when it comes to debugging attribute behavior with those undocumented scripting rules, at least when it was first released.
-- Scott
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list