[EXTERNAL] Re: unable to capture eppn information from SAML2/POST at SP

O'Quinn, Dennis DENNIS_OQUINN at homedepot.com
Tue Jun 12 09:32:05 EDT 2018


Thank you sir...  was just trying to make it fit into the paradigm of the rest of the product.  I will come up with my own 'broken' standard and reconfigure...  Esp. since now (before going production) is certainly the time to do it...

D



-----Original Message-----
From: users <users-bounces at shibboleth.net> On Behalf Of Peter Schober
Sent: Tuesday, June 12, 2018 9:29 AM
To: users at shibboleth.net
Subject: Re: [EXTERNAL] Re: unable to capture eppn information from SAML2/POST at SP

* O'Quinn, Dennis <DENNIS_OQUINN at homedepot.com> [2018-06-12 14:11]:
> RE: the name/id/eppn in the attribute map, yes, I did not understand 
> which parm was setting what, but, Scott set me straight on that and I 
> have switched it to name=eepn, id=eduPersonPrincipalName

While you can certainly do that (it's an arbitrary only internally meaningful string) I would not call it "eduPersonPrincipalName" mainly because IT IS NOT AN eduPersonPrincipalName ATTRIBUTE.

Keeping "eduPersonPrincipalName" as the name works around the issue that the software stops protecting it (the way it protects the internal attribute with an id of "eppn"), but that doesn't make it right -- or less confusing for your co-workers or successors -- to even more explicitly call it something which -- as I have pointed out -- it is not.
Call it "user-id" or "broken-crap-from-clueless-idp". Or whatever.

-peter
--
For Consortium Member technical support, see https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.shibboleth.net_confluence_x_coFAAg&d=DwICAg&c=MtgQEAMQGqekjTjiAhkudQ&r=mn6DeBt1nj8Oqx06pdIK0_n5EfK6FeVHgdjBNpchyro&m=vzkl1dz86XXVUbX86Iv7xs7gQ0C3rrJtfGAaRvmxAbY&s=9yl7_BF4OxWj0iXw6-N02BWB_j9pAwyDqO2FqpO5830&e=
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list