Reused usernames and persistentIds
Ramon Pfeiffer
ramon.pfeiffer at uni-tuebingen.de
Thu Oct 23 06:33:25 EDT 2014
Am 23.10.2014 um 10:09 schrieb Rhys Smith:
> On 23 Oct 2014, at 08:26, Ramon Pfeiffer <ramon.pfeiffer at uni-tuebingen.de> wrote:
>>
>> But as far as I can see, the IdPPersistentNameIdentifier as defined in the Shibboleth wiki [1] is based on the storedId which in turn is based on the username. Do I miss something?
>
> You can define which attribute is used as the input to the hash - you can make it username if you want, but equally you can make it any other attribute from any of your data connectors. Just change the sourceAttributeID value.
I see this.
Given it is such a bad practice to use the username (as mentioned by
Scott), it shouldn't appear like this on the wiki-page.
Ramon
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 5054 bytes
Desc: S/MIME Cryptographic Signature
Url : http://shibboleth.net/pipermail/users/attachments/20141023/dee6ffbd/attachment.bin
More information about the users
mailing list