[EXTERNAL] Re: unable to capture eppn information from SAML2/POST at SP
Cantor, Scott
cantor.2 at osu.edu
Tue Jun 12 09:00:22 EDT 2018
> Regarding the 'environment' concept, this (SAML?) is very oriented towards an
> educational environment from whence it came... However, I see that it is (or
> has) moved out of that realm into a more 'generic' environment. At the risk of
> opening a can of worms, I wonder if anyone has given thought to updating the
> documentation/references/nomenclature to something more generic.
That would depend on what you think should be changed. For example, SAML attribute names should be URIs. That's not an edu thing, it's a "this is how it's supposed to work" thing.
Our example files don't just include eduPerson attributes, there's a host of sample rules for basic stuff in there.
Scoping, to use another example, is not an edu thing, but a Shibboleth thing because I understood the implications of federated identifiers a lot earlier than the rest of the industry, and the bugs in products and services like Office 365 illustrate why I built all that.
Really, nothing in there is edu at all except for the default rules for a few eduPerson attributes, which itself is not inherently edu-specific in most respects.
We do things in SAML right (and we define the rules for what we do), and enterprises don't (*). Documenting "wrong" isn't really a goal.
-- Scott
(*) Yes, this is a generalization, but it's also largely true.
More information about the users
mailing list