Allowed values for NameIDFormat

Ian Bobbitt ibobbitt at globalnoc.iu.edu
Mon Oct 24 12:52:43 EDT 2016


I'm working on setting up authentication with a vended product that minimally supports SAML2 (Service Now). They only
look at the NameID, not any Attributes. I would prefer to send the same value as the ePPN for that, as opposed to one of
the standards (persistent is unintelligible, and email is under user control).

Is it better to use the urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified NameIDFormat and a Relying Party override
to force generating the NameID from ePPN, or can/should I setup a NameID generator for urn:oid:1.3.6.1.4.1.5923.1.1.1.6
(ePPN's OID URN) and drive the selection from a NameIDFormat element in the SP's metadata?

-- Ian

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 3639 bytes
Desc: S/MIME Cryptographic Signature
URL: <http://shibboleth.net/pipermail/users/attachments/20161024/1daed09c/attachment.p7s>


More information about the users mailing list