[EXTERNAL] Re: unable to capture eppn information from SAML2/POST at SP

Cantor, Scott cantor.2 at osu.edu
Tue Jun 12 09:00:22 EDT 2018


> Regarding the 'environment' concept, this (SAML?) is very oriented towards an
> educational environment from whence it came...  However, I see that it is (or
> has) moved out of that realm into a more 'generic' environment.  At the risk of
> opening a can of worms, I wonder if anyone has given thought to updating the
> documentation/references/nomenclature to something more generic.

That would depend on what you think should be changed. For example, SAML attribute names should be URIs. That's not an edu thing, it's a "this is how it's supposed to work" thing.

Our example files don't just include eduPerson attributes, there's a host of sample rules for basic stuff in there.

Scoping, to use another example, is not an edu thing, but a Shibboleth thing because I understood the implications of federated identifiers a lot earlier than the rest of the industry, and the bugs in products and services like Office 365 illustrate why I built all that.

Really, nothing in there is edu at all except for the default rules for a few eduPerson attributes, which itself is not inherently edu-specific in most respects.

We do things in SAML right (and we define the rules for what we do), and enterprises don't (*). Documenting "wrong" isn't really a goal.

-- Scott

(*) Yes, this is a generalization, but it's also largely true.


More information about the users mailing list