persitentID nameID for specific SPs, transient for default
Cantor, Scott
cantor.2 at osu.edu
Thu Dec 14 13:14:03 EST 2017
> I don't want to use inapropriate or old V2 solution, I just want to be able to
> connect to SPs that request an edupersonTargetedID
> so if NameID format in IDPv3 is the way to go , i will follow that path .
Then just follow that documentation.
> aacli with saml2, did'nt know about that option, good advice, here it is with
> previous edupersonTargetedID constructed manually from eppn :
That's an email address. You can't end up there by following any documentation on producing a persistent NameID.
> is that doc:
> https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPTargetedID
> the correct one to follow to create an eduPersonTargetedID as requested by
> SPs like
> https://monitor.eduroam.org/sp/module.php/saml/sp/metadata.php/defa
> ult-sp
> that publishes in their metadata :
No, it's a historical summary of all the horrible messes this all created, and an example of why the entire construct is over, dead, hopeless. The real answer is, we're dumping everything you're currently killing yourself to use because it's too hard to support and deal with and creating new attributes with simpler syntaxes to deal with this use case.
Having said that, people are not going to stop using this stuff any time soon, and if you want to generate a persistent NameID, just follow that explicit documentation for the IdP.
You had some attempt at that done, and I told you the configuration was broken and to look at the log. Then you went off in a totally different direction.
> I just want to be able to give that SP what it request. I've read too many
> specs, docs , best practices, i'am lost , which one should I follow to fullfill that
> SP ?
Generate a persistent NameID, that's it.
-- Scott
More information about the users
mailing list