Question about available attributes

Tom Scavo trscavo at gmail.com
Wed Jun 11 12:41:50 EDT 2014


On Wed, Jun 11, 2014 at 12:20 PM, Ken Weiss <ken.weiss at ucop.edu> wrote:
> Is there a set of attributes that every single Shibboleth IDP is required to
> release to every configured SP? At the very least, will a successful
> authentication result in the EPPN being returned to the SP?

This is a federation question, not a software question. The software
will do whatever it's configured to do.

> I know that for Research and Scholarship IDPs I should be able to count on
> EPPN, displayName (or equivalent), and mail, but what about non-R&S IDPs?
> What can I absolutely rely on obtaining from any IDP that allows my SP to
> interact with it?

There are no guarantees at all, which is why R&S was invented in the
first place, to address exactly this problem, at least for a
well-defined set of SPs.

I've pointed to this page before but let me do so again:

https://spaces.internet2.edu/x/x4HYAg

The idea is to tag IdPs that satisfy certain criteria that matter to
SPs. (The exact set of characteristics are open to discussion but I
suggest you bring this up on the InCommon participants list.) Note the
definition of "discoverable IdP," which is along the lines of what
you're asking.

Tom


More information about the users mailing list