NameID Format Generation
Michael Dahlberg
olgamirth at gmail.com
Sat Feb 27 19:32:36 EST 2016
I agree with you (about the SPs being brain dead), not because I can
distinguish between the merits of an SP requesting a set of attributes
versus requiring a NameID, but because dealing with the SPs that require a
NameID is infinitely more difficult that those requesting attributes.
However, when my boss says "Get SSO working with .... and we've already
signed a contract with them", I don't have the liberty to say "NO WAY, that
SP is brain dead".
Finally, thank you so much for the V3 documentation. I know you and others
did the V2 as well, but you made it significantly better; I especially like
the added examples.
Thanks,
Mike
On Sat, Feb 27, 2016 at 5:25 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> > The data the SP provides is the NameIDPolicy in the AuthnRequest and its
> > metadata, that's it.
>
> More to the point, no SP brain dead enough to need a NameID (or think they
> do) wil provide either of these inputs. Many federations (e.g. InCommon)
> don't support NameIDFormat elements in metadata, but a good number of cases
> where it even comes up aren't providing metadata anyway. The most common
> approach is to add it to the metadata you have to generate, or locally
> load, into the IdP.
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160227/5ac54f7d/attachment.html>
More information about the users
mailing list