common LDAP schemas to draw attribute definitions from

Cantor, Scott cantor.2 at osu.edu
Mon Jul 1 15:23:11 EDT 2019


On 7/1/19, 2:51 PM, "users on behalf of Liam Hoekenga" <users-bounces at shibboleth.net on behalf of liamr at umich.edu> wrote:

> For a similar reason, I'm also hesitant to use URLs, because I feel like they should resolve to relevant information.  I
> realize we could start to address both by improving documentation.

I guess my answer would be that, not having an OID tree anyway here, when I have to invent local names to use, I created an arc under urn:mace:osu.edu:shibboleth:attribute-def for my local attribute naming.

LDAP is immaterial, the IdP doesn't pass LDAP attributes out, it passes SAML, CAS, or OIDC. The purpose of OID naming is not to "expose" LDAP, it's to reuse names that are already publically standardized anyway.

-- Scott




More information about the users mailing list