building an AD userPrincipleName attribute

Rob Gorrell rwgorrel at uncg.edu
Thu Sep 10 15:32:22 EDT 2015


We are in the middle of deploying IU's Kumo application. Without getting
into what Kumo is, their SP needs to consume an attribute that matches our
Active Directory userPrincipleName. However, because AD is not our identity
store for shibb, and AD doesn't own the uncg.edu namespace, eppn !=
userPrincipleName. I'm also not too interested in storing AD UPN's in our
LDAP. So what I would like to do is be able to create a custom attribute by
taking our username (cn) and simply append a static string "@campus.uncg.edu"
matching our AD domain to form an representation of our AD UPN and release
this to Kumo.

I'm not very versed with attribute transformations, but I imagine this one
isn't too difficult, however I could use some guidance from the more SAML
savy in what an attribute definition for something like this might look
like. IU recommends we name this custom attribute "
https://schemas.uits.iu.edu/CloudStorage/Identity/UPN"

Thanks
-Rob


-- 
Robert W. Gorrell
Systems Architect, Identity and Access Management
University of NC at Greensboro
336-334-5954
PGP Key ID B36DB0CA
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20150910/aa739151/attachment.html>


More information about the users mailing list