computedID in idpv3
Paul B. Henson
henson at cpp.edu
Sun Feb 14 15:44:49 EST 2016
On Sat, Feb 13, 2016 at 05:42:15PM -0500, Tom Scavo wrote:
> The second issue is more interesting. Does your IdP support SAML2
> only? If so, that's a no-brainer since you don't need ePTID. All your
> needs are satisfied by SAML2 Persistent NameID.
We are SAML2 only, one of the bright sides of our painful domain name
change last year was I took the opportunity to deploy our new idp
without SAML1. I'm not sure I understand you though; I still have
eduPersonTargetedID in my attribute resolver config and my attribute filter
config, it still shows up in my idp-audit log, and I have SP's that are
consuming it. At least they say they're using it. So while my needs
might be satisfied by the SAML2 Persistent NameID if I have SP's that
are still using the eduPersonTargetedID I don't see how I could just get
rid of it?
I did configure the idpv3 persistent NameID to use the computedid with
the same source attribute and salt, so theoretically it should have the
same value as eduPersonTargetedID and I guess I could try to get them to
switch to using it and wean off of eduPersonTargetedID, but with some
SP's it's like pulling teeth to get them to do stuff <sigh>.
Thanks...
--
Paul B. Henson | (909) 979-6361 | http://www.cpp.edu/~henson/
Operating Systems and Network Analyst | henson at cpp.edu
California State Polytechnic University | Pomona CA 91768
More information about the users
mailing list