SAML attribute naming
Eric Goodman
Eric.Goodman at ucop.edu
Fri Oct 17 12:00:18 EDT 2014
So I've always assumed that the SAML spec called out the use of URNs for attribute naming. Reading the SAML spec looking for that, it appears the spec actually defines a standard for using LDAP/X.500 attribute encoding - which does require use of URNs for attribute naming - but does not require the use of that spec for SAML in general.
I'm currently working with a vendor that is asking for attributes with names (not friendly names) such as "firstname", "lastname", etc.
Do I have any grounds to argue that those are invalid attribute names, and try to convince/force the vendor to provide urns for these? I will ask them to, but I'm looking for something that backs up a claim that using such names is "wrong" rather than just "not the way we do things".
(FWIW, the vendor also defines several vendor-specfiic attributes that also have non-URN values, and since those are specific to this vendor the non-URN-ness of those attributes may not be as much of an issue for us.)
Thanks,
--- Eric
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20141017/5ab05691/attachment.html
More information about the users
mailing list