various nameid formats

Cantor, Scott cantor.2 at osu.edu
Wed Mar 22 13:45:18 EDT 2017


On 3/22/17, 1:33 PM, "users on behalf of Ramaiah, Vanna G." <users-bounces at shibboleth.net on behalf of ramaiah at musc.edu> wrote:

> So, for an SP that is requesting uid in nameID , should something like this help if I am using legacy attribute-resolver file?

Help how? Can you do it? Sure.

"uid" is so underdefined that it's essentially the poster child for "should never be used in a federated exchange", but it's equivalent to anything else when it's a point to point exchange with an application that inherently scopes itself to one IdP and one set of users. Those aren't federated, they're simply manual/bilateral data passing, could just as easily be another system on campus.

This is not about SAML, or Shibboleth. This is simply understanding data and its implications.

-- Scott




More information about the users mailing list