Persistent NameID Generation

Cantor, Scott cantor.2 at osu.edu
Wed Aug 31 15:11:30 EDT 2016


On 8/31/16, 3:05 PM, "users on behalf of Michael Dahlberg" <users-bounces at shibboleth.net on behalf of olgamirth at gmail.com> wrote:

>    I seem to be having a problem with persistent nameID generation.  One SP that we work
> with requires that we release the employeeNumber as a persistent nameID.

That is NOT an acceptable practice, so that should be the end of the conversation, just say no, and use a different Format.

I don't know of any SP outside of Microsoft misusing that Format that hasn't been easily convinced to stop. SPs don't care about Formats. They say they do but they don't, almost always. Just use the right Format.

> However, based on this debug output, it looks as if the nameID is being *computed* from
> the employeeNumber source attribute rather than the employeeNumber being just *used* as
> the nameID

Yes, because that's what a persistentID is, it's opaque. Making the system behave incorrectly is a lot of work and ends up with a messy configuration.

-- Scott




More information about the users mailing list