ldap v3 attribute descriptions
Cantor, Scott
cantor.2 at osu.edu
Sun Jan 12 13:26:56 EST 2014
On 1/10/14, 12:12 PM, "Mark K. Miller" <max at psu.edu> wrote:
>
>Is there a pointer to some 'best practices' guidance, or can someone
>offer
>specific guidance here about how to optimally handle these attribute
>descriptions in the Shibboleth attribute-resolver.xml (or some other shib
>config file?)
I can't speak to anything on the LDAP side, but FWIW, it was explicitly a
feature of LDAP that was not standardized for expressions in SAML, so
there is no standard way to communicate anything that happens to be
managed as an attribute option (I believe that's the term of art).
There have been occasional conversations about it, but it's a major
complexity increase to attach meta-information to attributes and pretty
much no SAML implementation would ever handle it (mine could fairly
easily, but it doesn't pay to standardize anything that only my code would
handle).
-- Scott
More information about the users
mailing list