IdPv3 - eduPersonTargetedID - How to define and release this attribute?
Waldbieser, Carl
waldbiec at lafayette.edu
Thu Mar 17 11:48:45 EDT 2016
What I am really interested in is configuring IdPv3 to support the global R&S category.
The information I have read[1][2] suggests that eduPersonTargetedID is recommended and possibly required to be released to support this category if ePPN doesn't fit certain criteria.
I am not sure if I am being precise enough, but according to those rules, and the fact that the ePPN for my institution was perhaps at one time reassignable, I think I need to do *something* with eduPersonTargetedID. I am not sure if I am supposed to release it as an attribute or if there is some other terminology.
I am open to suggestions as to how I might meet the goal of supporting R&S using IdPv3.
Thanks,
Carl
[1] https://spaces.internet2.edu/display/InCFederation/Research+and+Scholarship+IdP+Config
[2] https://spaces.internet2.edu/display/InCFederation/Research+and+Scholarship+Attribute+Bundle
----- Original Message -----
From: "Cantor, Scott" <cantor.2 at osu.edu>
To: "Shib Users" <users at shibboleth.net>
Sent: Thursday, March 17, 2016 11:29:02 AM
Subject: RE: IdPv3 - eduPersonTargetedID - How to define and release this attribute?
> From reading the docs, I gather that in order to ultimately release this
> attribute, I need to configure a persistent name ID generator [1]. However,
> once I have set up the generator, I am not sure what I am supposed to do
> next. Does the attribute get defined in `attribute-resolver.xml`? How is it
> defined? Once it is defined, can I release it via `attribute-filter.xml` the same
> way I would release any other attribute?
If you're trying to use eduPersonTargetedID as an attribute, the first steps are to question why, push back, and not to do it.
If you do need to do that for some legacy application that can't support persistent NameIDs or is SAML 1 only, then the only way to do it is to configure it the same way as it would have been in V2, using the resolver, and not with the documentation you're looking at. The ability is deprecated but removing it would be akin to removing SAML 1 support, not something that's going to happen any time soon.
-- Scott
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list