Persistent NameID

Cantor, Scott cantor.2 at osu.edu
Tue Feb 28 12:19:57 EST 2017


> I haven't been keeping a close eye on federation plans wrt their IdP Attribute
> Profiles (1). What is the recommended/expected replacement for SAML
> Persistent NameID? Something IdPO's generate themselves, such as
> eduPersonUniqueId?

While I personally have a lot of concerns about persistent IDs, my comment to the OP was not in regard to their goodness or badness, it was explaining that his particular scenario was in no way related to them at all.

I don't believe there's yet a real grasp of all the horrendous problems around identifiers right now, and I couldn't even hazard a guess as to the outcome of any discussion about it or even where it would happen, though there's an impending one in the InCommon deployment profile WG.

I will say that if you can generate persistent IDs, you can probably provide eduPersonUniqueID also with the same underlying data, and should support them, but you absolutely need to take very special care not to use any identifiers that can differ only in case. And that's one of the major problems with persistent IDs (and the OpenID sub claim).

I've already patched support for Base32 in place of Base64 encoding into the IdP, and I would not deploy persistent IDs from scratch at present without a custom fix applied to do that, which reminds me I need to make sure the documentation mentions that.

-- Scott



More information about the users mailing list