[EXTERNAL] Re: unable to capture eppn information from SAML2/POST at SP

O'Quinn, Dennis DENNIS_OQUINN at homedepot.com
Tue Jun 12 09:21:56 EDT 2018


Well, that wasn't a complaint or attack....  I am a firm believer of doing things the 'right' way from the beginning...  Remember, I am completely unfamiliar with this entire process, so, I don't really have enough of a knowledge base to even *consider* right vs. wrong...  and that's not quite what I meant...  I was thinking more of an 'evolution' as this process grows out of its root environment.  And I am not saying that the evolution is necessary or even applicable...  I am just voicing my own observations as a complete neophyte.

As for examples, yes, I noted the cn/ldap/email/other examples in the attribute map...

What I was really missing (and it is probably out there where I just haven't found it yet) was some sort of primer that tied at least the 3 (or more?) files together a little better...  Like the shibboleth2.xml (and metadata) vs. attribute-map vs. attribute-policy vs. ???...

it took me a bit to grasp the relationships between all of the pieces (i.e., the session info (shibboleth2.xml and metadata info) and the data items that could be manipulated (and how they could be manipulated, e.g. name vs. id in attribute-map) and how they could be filtered (attribute-policy.xml)...

I know that information is there collectively, but, if you have zero exposure to this stuff, then it's a little hard to piece it all together.

Also, I get the distinct impression from some of the group members that there is a pretty high expectation (or assumption?) of fore-knowledge on behalf of the users asking questions.   And that is reasonable given the relative levels of expertise between some of the responders vs. the users posting questions....  I certainly applaud your level of responsiveness....  I feel quite guilty with the level of responsiveness given the elementary level of some (or all) of my questions when someone that is writing the code for this project responds...  I think you guys may want to consider bumping your responses up to the really complex stuff and letting others in the group handle the little stuff...  That may reduce your load quite a bit...

And again, thanks for all the help with my 'education' on these concepts and processes...  It was really useful and appreciated...

Dennis


-----Original Message-----
From: users <users-bounces at shibboleth.net> On Behalf Of Cantor, Scott
Sent: Tuesday, June 12, 2018 9:00 AM
To: Shib Users <users at shibboleth.net>
Subject: RE: [EXTERNAL] Re: unable to capture eppn information from SAML2/POST at SP

> Regarding the 'environment' concept, this (SAML?) is very oriented 
> towards an educational environment from whence it came...  However, I 
> see that it is (or
> has) moved out of that realm into a more 'generic' environment.  At 
> the risk of opening a can of worms, I wonder if anyone has given 
> thought to updating the documentation/references/nomenclature to something more generic.

That would depend on what you think should be changed. For example, SAML attribute names should be URIs. That's not an edu thing, it's a "this is how it's supposed to work" thing.

Our example files don't just include eduPerson attributes, there's a host of sample rules for basic stuff in there.

Scoping, to use another example, is not an edu thing, but a Shibboleth thing because I understood the implications of federated identifiers a lot earlier than the rest of the industry, and the bugs in products and services like Office 365 illustrate why I built all that.

Really, nothing in there is edu at all except for the default rules for a few eduPerson attributes, which itself is not inherently edu-specific in most respects.

We do things in SAML right (and we define the rules for what we do), and enterprises don't (*). Documenting "wrong" isn't really a goal.

-- Scott

(*) Yes, this is a generalization, but it's also largely true.
--
For Consortium Member technical support, see https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.shibboleth.net_confluence_x_coFAAg&d=DwICAg&c=MtgQEAMQGqekjTjiAhkudQ&r=mn6DeBt1nj8Oqx06pdIK0_n5EfK6FeVHgdjBNpchyro&m=1_W5TKLhfn9lL4d035n3lYKNZrD46pXTBePCnY_dLXE&s=APhyFl6zEoSKN3Sj-Bj7dTV7u32r12FFjBTdoRpTAL0&e=
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list