persitentID nameID for specific SPs, transient for default

Peter Schober peter.schober at univie.ac.at
Tue Dec 19 10:05:01 EST 2017


* Jehan Procaccia <jehan.procaccia at tem-tsp.eu> [2017-12-19 15:29]:
> I wrote to SPs technical contact with that long thread we had here as a
> reference , I'am waiting for a reponse, but if someone on the list can
> confirme that he/she can acces that SP I would be assured that the pb still
> reside on my IDP  and not monitor.eduroam.org SP !

Try this URL for testing:
https://monitor.eduroam.org/sp/module.php/core/authenticate.php?as=default-sp
After login you should see successfully processed attributes.

Note that you're now sending both the eduPersonTargetedID SAML
Attribute (with a SAML 2.0 NameID as its AttributeValue) and the same
SAML NameID in the Assertion's Subject element.  (The old eduGAIN
attribute profile recommended this, while Scott called it the "worst
of all options", IIRC.)
That shouldn't be necessary, neither for the eduroam SP nor for any
RENATER services, but also isn't the source of any issues you're still
having. (And at least you could now decide to release only one or the
other, since you have both methods configured and working.)

Also note that you're sending too much info to that SP (ePPN, email,
uid all in /addition/ to an identifier that's meant to preserve your
privacy), but those are "just" data minimisation/protection issues and
would not stop this service from working.

-peter


More information about the users mailing list