Shibboleth Identity Provider 3.2.1 custom authentication configuration
Cantor, Scott
cantor.2 at osu.edu
Mon Jul 11 17:33:24 EDT 2016
On 7/11/16, 5:22 PM, "users on behalf of Raymond Gardner" <users-bounces at shibboleth.net on behalf of r.gardner at ntta.com> wrote:
> [Raymond Gardner] You seem to be losing me. This is not a SP requirement. All the SP
> cares about is that the Subject -> NameID is valid as well as any extra attributes.
> These are authentication requirements. The IdP is responsible for authentication.
I thought you phrased this originally as needing to do something for a specific SP, so I took that to mean it wasn't a routine thing.
> [Raymond Gardner] I'm just trying to transform the username. Whether that happens by
> regular expression or by a mapping stored in a database, it shouldn't matter.
> If the application doesn't support this, then the application doesn't support it. That is
> fine.
It *does* matter what that step is, if the code is written to assume a regular expression, which it was. If you want a feature to extend that with an interface that's more pluggable, you can certainly file a request for that.
-- Scott
More information about the users
mailing list