v3 Docs Q: Appropriate use of idp.authn.LDAP.returnAttributes?
Daniel Fisher
dfisher at vt.edu
Wed Jul 1 10:59:47 EDT 2015
On Tue, Jun 30, 2015 at 9:38 AM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> On 6/29/15, 10:58 PM, "users on behalf of Daniel Fisher" <
> users-bounces at shibboleth.net on behalf of dfisher at vt.edu> wrote:
> >
> >One reason to pull attributes during authentication is that it is the
> only time you can read attributes as the authenticating user. For some
> directory implementations it is attractive to simply exercise the user ACLs
> rather than configuring a service account to read that data.
>
> While that's true, it isn't as simple to punt everything the data
> connector does over to this step.
I didn't mean to suggest that, just that I see some potential problems
being solved here. The primary intent was indeed exposing data to the
authentication flow.
--Daniel Fisher
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20150701/8f9cf147/attachment.html>
More information about the users
mailing list