persitentID nameID for specific SPs, transient for default
Jehan Procaccia
jehan.procaccia at tem-tsp.eu
Thu Dec 14 18:05:09 EST 2017
Le 14/12/2017 à 19:14, Cantor, Scott a écrit :
> Then just follow that documentation.
which one ? probably
https://wiki.shibboleth.net/confluence/display/IDP30/PersistentNameIDGenerationConfiguration
can you confirm ?
>> is that doc:
>> https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPTargetedID
>> the correct one to follow to create an eduPersonTargetedID as requested by
> No, it's a historical summary of all the horrible messes this all created, and an example of why the entire construct is over, dead, hopeless. The real answer is, we're dumping everything you're currently killing yourself to use because it's too hard to support and deal with and creating new attributes with simpler syntaxes to deal with this use case.
indeed , i've been lost in that "horrible mess" ...
>
> Having said that, people are not going to stop using this stuff any time soon, and if you want to generate a persistent NameID, just follow that explicit documentation for the IdP.
>
> You had some attempt at that done, and I told you the configuration was broken and to look at the log. Then you went off in a totally different direction.
>
>> I just want to be able to give that SP what it request. I've read too many
>> specs, docs , best practices, i'am lost , which one should I follow to fullfill that
>> SP ?
> Generate a persistent NameID, that's it.
if you confirm that doc:
https://wiki.shibboleth.net/confluence/display/IDP30/PersistentNameIDGenerationConfiguration
there are /computed IDs/ or /stored IDs/ , which one do you recommend me ?
thanks .
jehan
>
> -- Scott
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20171215/78733211/attachment.html>
More information about the users
mailing list