IdPv3 - eduPersonTargetedID - How to define and release this attribute?
Tom Scavo
trscavo at gmail.com
Thu Mar 17 18:57:52 EDT 2016
On Thu, Mar 17, 2016 at 6:47 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> On 3/17/16, 6:31 PM, "users on behalf of Tom Scavo" <users-bounces at shibboleth.net on behalf of trscavo at gmail.com> wrote:
>
>>The REFEDS Research & Scholarship specification [1] is very clear about this:
>>
>><quote>
>>For the purposes of access control, a non-reassigned persistent
>>identifier is required. If your deployment of eduPersonPrincipalName
>>is non-reassigned, it will suffice. Otherwise you MUST release
>>eduPersonTargetedID (which is non-reassigned by definition) in
>>addition to eduPersonPrincipalName.
>></quote>
>
> First sentence in eduPerson's definition of ePTID:
>
> eduPersonTargetedID is an abstracted version of the SAML V2.0 Name
> Identifier format of
> "urn:oasis:names:tc:SAML:2.0:nameid-format:persistent"
>
> It can't be much more explicit than that. The NameID is perfectly adequate.
Oh sorry, I didn't realize that was the question. Yes, I would agree
with that, but that should be clarified in the FAQ linked at the
bottom of the specification.
For the record, the point I was trying to make was: ePTID shouldn't be
a strict requirement for R&S. As it turns out, eduPersonUniqueId is
actually a better choice (but ePUId didn't exist at the time the R&S
spec was written).
Tom
More information about the users
mailing list