Problem with unscoped eppn - Shib SP and ADFS IdP
Cathy Scott
cathystill at gmail.com
Fri Sep 25 13:33:24 EDT 2015
Thanks again Scott. Your insights and assistance is greatly appreciated.
On Fri, Sep 25, 2015 at 10:30 AM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> On 9/25/15, 1:05 PM, "users on behalf of Cathy Scott" <
> users-bounces at shibboleth.net on behalf of cathystill at gmail.com> wrote:
>
> >Yes, changing the decoder back to ScopedAttributeDecoder resolved the
> issue. This is a dedicated environment and will never have any other IdP
> authenticating in the environment. I do want to employ best practice.
>
> The best practice is to stick to standardized attribute (not EPPN
> necessarily, but there are in fact no standard identifier attributes in the
> world except for the ones we defined). But that would imply not creating
> mappings in the SP for any proprietary attributes from ADFS.
>
> Since you did that, you're basically creating work on both ends. You added
> the mappings, and they apparently mapped the claim name into an EPPN. I'm
> saying pick one option, basically. Either they send standard stuff, or you
> map non-standard stuff.
>
> Also, the better practice is not to just delete the scope checking. You
> can alter the metadata supplied by ADFS that you load to add in the Scope
> extension that authorizes the scoped values. That assumes the metadata
> isn't coming from a federation that's already curating the metadata and
> already provides the Scope extension, which is the actual best practice.
>
> > May I ask what the risk is and why you would not make these changes?
> Is there a better way to integrate with ADFS IdP?
>
> Doing things incorrectly or confusingly creates a mess for somebody else
> to cleanup when they inevitably inherit an pile of unexplained settings and
> then have to go ask for help.
>
> I don't really understand any of the changes made or why they were made.
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20150925/311b4de2/attachment-0001.html>
More information about the users
mailing list