Scoped eppn question
Greg Haverkamp
gahaverkamp at lbl.gov
Mon Jan 13 17:32:10 EST 2020
On Mon, Jan 13, 2020 at 2:19 PM Bryan Wooten <bryan.wooten at utah.edu> wrote:
> Our IDP returns scoped eppn but our Grouper instance wants unscoped for
> our Grouper subjectID filter. (We had success with CAS for SSO)
>
>
>
> Is there a way to define unscoped eppn for any given SP? Either on the IDP
> side or SP side?
>
ePPN is scoped by definition. The simplest answer is that you just need an
unscoped attribute like uid. (I don't know how many folks federate their
Grouper installations across authentication realms, so I'm not sure how far
beyond the simple case one needs to worry.)
The Grouper wiki has some documentation:
https://spaces.at.internet2.edu/display/Grouper/Authentication+to+the+Grouper+UI
Greg
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20200113/6bbc9751/attachment.html>
More information about the users
mailing list