Shibboleth IdP not passing AD LDAP attributes to TestShib SP

Matthew X. Economou xenophon at irtnog.org
Wed Dec 13 09:41:35 EST 2017


Peter Schober writes:

> So more commonly you'd limit release of these attributes to R&S SPs.

I'm of the opinion that the REFEDS R&S attribute bundle should be
released by default, as it doesn't disclose anything you wouldn't
disclose yourself by emailing someone.  Furthermore, not releasing an
identifier with the semantics of ePPN, ePUID, or (worst case) ePTID
greatly limits the utility of SAML for the use cases in which I'm
primarily interested, although I understand that this opinion isn't
shared by everyone in the research/higher-ed community.

> If you don't ask for attributes in an LDAP search operation the LDAP
> DSA will simply return all the attributes your DN has permissions to
> see.  You only set returnAttributes to *limit* the attributes you want
> the DSA to return.

I didn't know that.  Thanks for the correction!

-- 
"The lyf so short, the craft so longe to lerne."



More information about the users mailing list