Releasing same NameID to all service providers

Cantor, Scott cantor.2 at osu.edu
Wed Mar 18 15:35:58 EDT 2015


On 3/18/15, 3:26 PM, "Tom Scavo" <trscavo at gmail.com> wrote:

>On Wed, Mar 18, 2015 at 2:30 PM, Alex Olson <ako at byu.edu> wrote:
>> Is there a significant vulnerability in releasing a standard persistent
>> nameID (like a uid) that is the same to all service providers?
>
>Scott addressed the privacy issue but you are essentially asking about
>eduPersonUniqueId (as I understand it). You can google for that...

Yes, and it bears noting in that vein, there is literally no such thing as a standard "persistent nameID that is the same to all SPs" in SAML. No NameID format exists with that definition, and not even many attributes like this have been defined.

uid is not suitable, it is not defined as a globally unique value.

The world uses email address as a stand-in for this concept, and all the other attempts globally to define such a thing have failed or are proprietary to a single "IdP" (using the term loosely).

-- Scott



More information about the users mailing list