Shibboleth Identity Provider 3.2.1 custom authentication configuration

Cantor, Scott cantor.2 at osu.edu
Mon Jul 11 17:33:24 EDT 2016


On 7/11/16, 5:22 PM, "users on behalf of Raymond Gardner" <users-bounces at shibboleth.net on behalf of r.gardner at ntta.com> wrote:

> [Raymond Gardner] You seem to be losing me.  This is not a SP requirement.  All the SP
> cares about is that the Subject -> NameID is valid as well as any extra attributes.
> These are authentication requirements.  The IdP is responsible for authentication.

I thought you phrased this originally as needing to do something for a specific SP, so I took that to mean it wasn't a routine thing.

> [Raymond Gardner] I'm just trying to transform the username.  Whether that happens by
> regular expression or by a mapping stored in a database, it shouldn't matter.
> If the application doesn't support this, then the application doesn't support it. That is
> fine.

It *does* matter what that step is, if the code is written to assume a regular expression, which it was. If you want a feature to extend that with an interface that's more pluggable, you can certainly file a request for that.

-- Scott




More information about the users mailing list