adobe creative cloud's attribute requirements
Rob Gorrell
rwgorrel at uncg.edu
Fri Mar 31 11:40:58 EDT 2017
I know several of you have integrated shibboleth with adobe creative cloud
and we just got done doing so as well and getting acquainted with some of
the, lets just say, "nuances" around their particular integration (odd
nameID formats, propensity for requiring custom attrb definitions using
friendlyName, slight-of-hand InCommon integration, etc). But beyond all
that, one thing thats bothered me and doesn't make much sense is their
desire to consume 3 attributes (FirstName, LastName, and Email) but
seemingly do nothing with them? Has anyone noticed this?
https://helpx.adobe.com/enterprise/kb/configure_shibboleth_idp_for_use_with_Adobe_SSO.html
We provision our users in Creative Cloud through API, setting values for
these 3 attributes. My assumption with Adobe wanting these as part of the
assertion is they would update/maintain the cloud with the values in the
assertion each time a user logged in (or maybe would even offer SSO dynamic
provisioning for those that didn't wish to do API provisioning though I've
not encountered such an option on their end).
But best I can tell, no matter what values for these attributes are in the
assertion and how much they differ, Adobe ignores them and sticks to the
provisioned values from the cloud. So then I told myself, why bother
sending them at all, and filtered them out of my attribute-filter... but
Adobe griped and the integration broke.
So my question, aimed at Adobe and those that might know more than me about
this, why require 3 attributes that you seemingly do nothing with? I don't
like sending university info to an outside vendor for no good reason.
-Rob
--
Robert W. Gorrell
IT Manager, Identity and Access Management
University of NC at Greensboro
336-334-5954 <%28336%29%20334-5954>
PGP Key ID B36DB0CA
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170331/a3503861/attachment-0001.html>
More information about the users
mailing list