Attribute naming help

Christopher Bongaarts cab at umn.edu
Tue Mar 4 12:14:53 EST 2014


On 3/4/2014 10:48 AM, Powers, John George wrote:
> So I am working on an existing Shibboleth Identity Provider, and I 
> realized that none of the attribute OID names match up with the 
> conventional names.  Now I am working with a Service Provider, and am 
> hoping this won't become a problem (especially since there are other 
> service providers that use this IdP).
>
> I have some limited experience on the Service Provider side.  Is this 
> a problem for a service provider?  I know service providers can map 
> different attributes to different local names, but do they have this 
> level of control for each identity provider that they are working with.
>
> For an example:
> Institution A names their 'last name' attribute urn:oid:1.2.3.4
> Institution B names their 'last name' attribute urn:oid:1.3.2.4
>
> Can a service provider say to use urn:oid.1.2.3.4 for Institution A 
> and urn:oid.1.3.2.4 for Institution B?
>
> If not, I am worried that I will have to change all the attributes to 
> use the standard OID definitions in the IdP, and then need to contact 
> all other service providers to account for this change.

You can work around it on the IdP side by defining additional attributes 
that encode to the proper names, and using attribute filters to 
selectively release either the wacky versions or proper versions 
depending on the SP.

-- 
%%  Christopher A. Bongaarts   %%  cab at umn.edu          %%
%%  OIT - Identity Management  %%  http://umn.edu/~cab  %%
%%  University of Minnesota    %%  +1 (612) 625-1809    %%

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140304/042b22a0/attachment.html 


More information about the users mailing list