PersistentNameIDGenerationConfiguration: Type 4 UUID

Hugo Slavia hugoslavia101 at gmail.com
Mon Jan 29 16:36:01 EST 2018


Thanks.

>Supporting the new attributes is going to necessitate doing it all in the
resolver so that is likely it.

Via attribute-resolver -- Is it possible to configure for UUID to be issued
on the first entry for user (per SP) --  storedonto SHIBID table?  Pairwise
ID not required.

If not possible -- we may go with Hash.


> The NameID support in the IdP is about commercial SAML integrations, none
of which will ever rely on any form of pairwise ID.

Yup -- make sense.




On Mon, Jan 29, 2018 at 1:27 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:

> > So on longer term -- if we wish to leverage persistence ID (i.e. unique
> to the
> > user per IdP/SP combination) --- where available both as SAML2String and
> as
> > a SAML2NameID -- what is the best configuration option?
>
> Supporting the new attributes is going to necessitate doing it all in the
> resolver so that is likely it. The NameID support in the IdP is about
> commercial SAML integrations, none of which will ever rely on any form of
> pairwise ID.
>
> -- Scott
>
> --
> For Consortium Member technical support, see https://wiki.shibboleth.net/
> confluence/x/coFAAg
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20180129/61afdf69/attachment.html>


More information about the users mailing list