Configuring RemoteUser checkHeaders in IDP3

Cantor, Scott cantor.2 at osu.edu
Wed Jul 13 17:47:45 EDT 2016


On 7/13/16, 5:19 PM, "users on behalf of Rich Graves" <users-bounces at shibboleth.net on behalf of rgraves at carleton.edu> wrote:

> I looked at c14 but ended up doing it the "dumb" way, by searching AD for mail instead of
> samaccountname, because really, why not?

No real reason. The c14n way is sometimes better for logging or because it addresses issues like linking to Duo or some other MFA solution where you need to get the usernames cleaned up early. Ultimately it's just style.

> They could have protected /idp/Authn/RemoteUser with a shibboleth SP and Google's SAML
> IDP

Really? I'm not aware of that being possible. They have IdPs that bridge back to enterprise logins, but I didn't think they actually did Google account -> SAML directly.

-- Scott





More information about the users mailing list