Interest of NameIDFormat in entity metadata
Guillaume Rousse
guillaume.rousse at renater.fr
Fri Dec 9 13:06:21 UTC 2022
Hello.
I'm a bit curious about the interest of the NameIDFormat element in
entity metadata. According to the specification, it is used to advertise
formats supported by an entity:
Zero or more elements of type anyURI that enumerate the name identifier
formats supported by this system entity acting in this role. See Section
8.3 of [SAMLCore] for some possible values for this element
As the format used is given alongside the NameID itself in SAML message,
mentionning it in metadata seems a bit useless. The only use case I see
would be to help an IdP supporting multiple formats to select the
correct one in its response, if the SP explicitely mention what it wants
in its metadata. But I don't see the need for an IdP to enumerate
supported formats, for instance, at least for automated processing.
Am I missing something here ?
Regards.
--
Guillaume Rousse
Direction des Services Applicatifs
RENATER - Paris
Tel: +33 1 53 94 20 45
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 2256 bytes
Desc: Signature cryptographique S/MIME
URL: <http://shibboleth.net/pipermail/users/attachments/20221209/7ea8636f/attachment.p7s>
More information about the users
mailing list