ADFS 2 as Shib Proxy

Cantor, Scott cantor.2 at osu.edu
Thu Aug 31 16:03:32 EDT 2017


> Yeah, let’s just say that’s not a supportable option (putting local school
> addresses into the central LDAP server).  Won’t go into the details on-list.

Had to be suggested.

My suggestion might not have been clear, but what I was trying to say was that rather than build claim rules to turn SAML attributes into MS attributes, you could just configure the IdP to encode them as MS attributes. The claim language in ADFS is both horrid, but more to the point undocumented in any real sense. But perhaps that's a problem due to what Dropbox expects to get not matching what ADFS would send it.

-- Scott



More information about the users mailing list