ldap v3 attribute descriptions
Mark K. Miller
max at psu.edu
Mon Jan 13 15:29:33 EST 2014
Scott, thank you! This background and perspective is quite helpful!!!
Max
On Sun, 12 Jan 2014, Cantor, Scott wrote:
> On 1/10/14, 12:12 PM, "Mark K. Miller" <max at psu.edu> wrote:
>>
>> Is there a pointer to some 'best practices' guidance, or can someone
>> offer
>> specific guidance here about how to optimally handle these attribute
>> descriptions in the Shibboleth attribute-resolver.xml (or some other shib
>> config file?)
>
> I can't speak to anything on the LDAP side, but FWIW, it was explicitly a
> feature of LDAP that was not standardized for expressions in SAML, so
> there is no standard way to communicate anything that happens to be
> managed as an attribute option (I believe that's the term of art).
>
> There have been occasional conversations about it, but it's a major
> complexity increase to attach meta-information to attributes and pretty
> much no SAML implementation would ever handle it (mine could fairly
> easily, but it doesn't pay to standardize anything that only my code would
> handle).
>
> -- Scott
>
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>
More information about the users
mailing list