PersistentSAML2NameIDGenerator requires releasing attributeSourceIds

Marvin Addison marvin.addison at gmail.com
Fri Apr 10 10:06:56 EDT 2015


>
> It's intentional (and should be documented that way).
>

Indeed it is documented [1]:

It must be released (in terms of attribute filter policy) to the relying
party, but need not have any attribute encoders attached (which means it
won't actually be visible to the relying party in the SAML response).

Obviously I haven't made my way through all the v3 docs yet.

If I didn't do it that way, handling custom NameID formats that actually
> expose data would have either been accident-prone or I would have have had
> to somehow completely separate different NameID types and generate them in
> different places


I have to admit I don't understand your justification in detail, but I
trust you. In any case I can meet my needs by not attaching an encoder to
the source attribute to prevent disclosure.

M <users-unsubscribe at shibboleth.net>

[1]
https://wiki.shibboleth.net/confluence/display/IDP30/NameIDGenerationConfiguration#NameIDGenerationConfiguration-PersistentIdentifierGeneration
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20150410/82cead35/attachment.html 


More information about the users mailing list