Interest of NameIDFormat in entity metadata

Guillaume Rousse guillaume.rousse at renater.fr
Fri Dec 9 13:06:21 UTC 2022


Hello.

I'm a bit curious about the interest of the NameIDFormat element in 
entity metadata. According to the specification, it is used to advertise 
formats supported by an entity:
Zero or more elements of type anyURI that enumerate the name identifier 
formats supported by this system entity acting in this role. See Section 
8.3 of [SAMLCore] for some possible values for this element

As the format used is given alongside the NameID itself in SAML message, 
mentionning it in metadata seems a bit useless. The only use case I see 
would be to help an IdP supporting multiple formats to select the 
correct one in its response, if the SP explicitely mention what it wants 
in its metadata. But I don't see the need for an IdP to enumerate 
supported formats, for instance, at least for automated processing.

Am I missing something here ?

Regards.
-- 
Guillaume Rousse
Direction des Services Applicatifs
RENATER - Paris
Tel: +33 1 53 94 20 45
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 2256 bytes
Desc: Signature cryptographique S/MIME
URL: <http://shibboleth.net/pipermail/users/attachments/20221209/7ea8636f/attachment.p7s>


More information about the users mailing list