Reused usernames and persistentIds

Ramon Pfeiffer ramon.pfeiffer at uni-tuebingen.de
Thu Oct 23 06:33:25 EDT 2014


Am 23.10.2014 um 10:09 schrieb Rhys Smith:
> On 23 Oct 2014, at 08:26, Ramon Pfeiffer <ramon.pfeiffer at uni-tuebingen.de> wrote:
>>
>> But as far as I can see, the IdPPersistentNameIdentifier as defined in the Shibboleth wiki [1] is based on the storedId which in turn is based on the username. Do I miss something?
>
> You can define which attribute is used as the input to the hash - you can make it username if you want, but equally you can make it any other attribute from any of your data connectors. Just change the sourceAttributeID value.

I see this.
Given it is such a bad practice to use the username (as mentioned by 
Scott), it shouldn't appear like this on the wiki-page.

Ramon

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 5054 bytes
Desc: S/MIME Cryptographic Signature
Url : http://shibboleth.net/pipermail/users/attachments/20141023/dee6ffbd/attachment.bin 


More information about the users mailing list