best practice naming local SAML attribute

Cantor, Scott cantor.2 at osu.edu
Wed Apr 15 17:01:27 EDT 2020


On 4/15/20, 4:57 PM, "users on behalf of IAM David Bantz" <users-bounces at shibboleth.net on behalf of dabantz at alaska.edu> wrote:

> there is rough consensus on best practice for naming a local SAML attribute as a URL that resolves to a description of
> the attribute.

I have never seen any justification for that having any value, and I don't believe it does.

I use urn:mace:osu.edu:shibboleth:attribute-def for mine, but using a URL would be ok. I don't have an OID arc to use.

But I would not, and would have no way to, make such a URL resolve to a stable result. It wouldn't be worth the hassle to worry about it, and since I had the existing URN namespace to avoid that whole problem, it was an unambiguous win to me.

The semantic web failed. I see no reason to keep beating that dead horse.

-- Scott




More information about the users mailing list