IdPv3 and Hathitrust: how to resolve and release SAML

Cantor, Scott cantor.2 at osu.edu
Mon Jul 10 12:48:36 EDT 2017


> In the worst case, we probably could resolve sAMAccountName or some
> other attribute to eppn, but it seems best to be able to use
> persistentNameID based on the above description.

It is not best to produce unstable persistent IDs. That's a responsibility of yours, it has nothing to do with the service. If your sAMAccountName values are unstable, or in any way technology dependent, then they are not appropriate.

What one service may or may not be able to handle isn't relevant. One service may react to an ID change with a relatively minor inconvenience, but another could cause a major service headache.

> We use active directory in the backend for authentication. What is generally
> recommended as the seed for computedID?

A value generated by an IDM registry or ERP system of record that you have a high degree of confidence doesn't change for any but the most serious of reasons or because you explicitly want it to.

My IdP does not support this because I cannot commit to that.

-- Scott



More information about the users mailing list