Help with Active Directory LDS properties

Peter Schober peter.schober at univie.ac.at
Thu Apr 16 05:43:01 EDT 2015


* Ranil De Silva <ranil.desilva at industrieit.com> [2015-04-16 11:31]:
> But I am not exposing any attributes.

With the exception mentioned below the software does not decide what
data to send where by itself. You'll need to configure the software to
do what you want.
Maybe you did so, but since you didn't ask anything specific about
that, I'll mention it.

> The Spring SAML app seems to show an encrypted string for name.

The only piece of data an IDP will release by default is a transient
NameID. It means nothing (so is not encrypted, that's the literal
value) and is only valid for a couple of minutes.
It doesn't have a use except for specific deployments, mostly
SAML1-related (e.g. attribute queries).

Everything else you'll have to tell the software yourself.
-peter


More information about the users mailing list