PersistentSAML2NameIDGenerator requires releasing attributeSourceIds

Cantor, Scott cantor.2 at osu.edu
Fri Apr 10 12:52:02 EDT 2015


On 4/10/15, 10:34 AM, "Peter Schober" <peter.schober at univie.ac.at> wrote:

>* Marvin Addison <marvin.addison at gmail.com> [2015-04-10 16:07]:
>> I have to admit I don't understand your justification in detail, but I
>> trust you. In any case I can meet my needs by not attaching an encoder to
>> the source attribute to prevent disclosure.
>
>So if I wanted to release the source attribute to some, but to others
>only the NameID generated from it? That's a very common scenario I
>would guess (e.g. source attribute being uid, for those lacking a
>persistent not-name-based identifier in their SORs)?

I hadn't considered the release issue from the opposite perspective, I was focused on the case of formats like Email Address, and being able to configure a generator for that without having to attach conditions to the generator that limit which RPs it runs for.

But the answer is that you would define two different attributes, one internal and one with the encoders.

Fair point though. I don't know, given all the interacting constraints, how much I can improve the situation, but I'll think about it.

-- Scott



More information about the users mailing list