IdPv3 and Hathitrust: how to resolve and release SAML
Tom Scavo
trscavo at gmail.com
Mon Jul 10 12:56:09 EDT 2017
On Mon, Jul 10, 2017 at 12:40 PM, Wang, Lihua <lwang2 at gc.cuny.edu> wrote:
>
> Below is from Sp's web site:
>
> "SAML V2.0 persistent NameID (urn:oasis:names:tc:SAML:2.0:nameid-format:persistent) OR eduPersonTargetedID (required) - to offer collection-building services
> If an institution does not yet have support for persistent NameID or eduPersonTargetedID, we will accept eduPersonPrincipalName with the understanding that if a user's eduPersonPrincipalName were to change, their saved personalized HT environment would no longer be available to them."
There's a misunderstanding here. All three of the identifiers
mentioned above are *persistent* but that is not the same as
*permanent*. In fact, NONE of them are defined to be permanent
identifiers so the SP should not care based on that characteristic
alone.
That said, eduPersonPrincipalName is less desirable as an identifier
since, unlike the other two, it may be reassigned. The consequences of
reassignment are more serious since an unauthorized user may be
granted access to the resource.
Tom
More information about the users
mailing list