Blackboard Transact and IdP 3

Cantor, Scott cantor.2 at
Tue May 24 14:55:28 EDT 2016

> Ugghh. With "something like ePPN" as value?
> Getting worse still.

That's probably not a requirement, I doubt they care or notice what's in it.

People make lots of assumptions and do things with trial and error rather than systematically.

> Care to share your configuration how you got the Shib IDP to resolve
> incoming (as part of Attribute Queries) NameIDs of type transient (!)
> with "something like ePPN" as the value?
> Even thinking about that makes my head hurt.

In V2 it's nothing more than adding a PrincipalConnector with that Format assigned I imagine. Certainly not a good idea since it's usable by any SP with a trusted credential. At least in V3 you can conditionalize the capability by SP.

-- Scott

