[EXTERNAL] Re: unable to capture eppn information from SAML2/POST at SP
Cantor, Scott
cantor.2 at osu.edu
Mon Jun 11 15:22:31 EDT 2018
> NOTE: we are not an educational entity, does the 'edu' prefix on all this stuff =
> "education"?
Yes, but the attribute itself is just a thing, it either matches your intended purpose or not. You shouldn't call a vegetable a fruit, but you don't have to be a member of the Fruit Association to use the fruit.
The "id" values inside the SP are just that, internal, but it just breeds confusion to use names that have meaning to people who look at these configs and mean something different.
> Are you saying I need to go back to my IdP team and have them convert that
> attribute to
He's saying don't call it EPPN if you don't do that, because it isn't.
> *now* I know what 'eppn' stands for... Thanks for that. However, we are not
> looking for an email address in return, we are only looking for the users LDAP
> ID (in this particular example the string 'dxo5ic1') and or intent is to have the
> REMOTE_USER field in the headers to be populated with that value.
For non-federated use internally, the uid attribute in LDAP, for which there may or may not be an example rule in the config, would be a reasonable choice to use.
-- Scott
More information about the users
mailing list