Question about available attributes
Ken Weiss
ken.weiss at ucop.edu
Wed Jun 11 12:56:15 EDT 2014
That answers my question. Thanks, Tom and Kevin.
--Ken
------------------------------------------------------------
Ken Weiss ken.weiss at ucop.edu
UC Office of the President 510-587-6311 (office)
California Digital Library 916-905-6933 (mobile)
UC Curation Center
415 20th Street, 4th Floor
Oakland, CA 94612
On 6/11/14 9:27 AM, "Kevin Foote" <kpfoote at uoregon.edu> wrote:
>
>On Jun 11, 2014, at 9:20 AM, Ken Weiss <ken.weiss at ucop.edu> wrote:
>
>> Is there a set of attributes that every single Shibboleth IDP is
>>required to release to every configured SP? At the very least, will a
>>successful authentication result in the EPPN being returned to the SP?
>
>No such set. An IdP is free to send all, some or none of the attributes
>it obtains for the principal it has authenticated.
>You can plan on getting a statement back I guess.
>
>> I know that for Research and Scholarship IDPs I should be able to count
>>on EPPN, displayName (or equivalent), and mail, but what about non-R&S
>>IDPs? What can I absolutely rely on obtaining from any IDP that allows
>>my SP to interact with it?
>
>See above.. R&S IdPs are saying that they will provide these attributes
>to R&S services not others.
>
>--------
>thanks
> kevin.foote
>--
>To unsubscribe from this list send an email to
>users-unsubscribe at shibboleth.net
More information about the users
mailing list