attribs from db what jaas uses
Cantor, Scott
cantor.2 at osu.edu
Wed Jun 25 18:29:52 EDT 2014
> regarding the name space what others also mentioned, do you mean the
> well determined OIDs and URNs? Is there a recommended way for them?
No, we mean your usernames. You can't chain together authentication sources unless you guarantee no user with the same username appears in both unless it's the same user.
> Because as I understand that I can guarantee that the intersection of user
> stores is nil, I can use the same attrib names.
I don't understand what you're trying to say there, but one has nothing to do with the other.
> Regarding SPs, they are usually able to use one IdP at the same time at least I
> saw only these.
That is, again, untrue, but also unrelated to the question you asked, so I still don't understand the relevance unless you're saying you'd rather have one IdP for each data store. If that's what you want, that's ok, but it's not fine if users have no idea what those data stores mean. They have to choose the IdP somehow. If it's one organization and one set of users, and you just don't have a reasonable IDM system to bring them all together, users shouldn't be exposed to that.
When your IDM situation sucks, using the IdP to hide all that and abstract it away from users and apps is a reasonable strategy, which I can vouch for from long personal experience.
-- Scott
More information about the users
mailing list