Duplicate attribute values in IdP 4.2
Cantor, Scott
cantor.2 at osu.edu
Mon May 16 19:28:10 UTC 2022
On 5/16/22, 2:53 PM, "users on behalf of Baron Fujimoto" <users-bounces at shibboleth.net on behalf of baron at hawaii.edu> wrote:
> TBH, we had a consultant provide us with the upgrade from 3.2.1 to 4.1 for expediency since it was a bigger
> leap and we possibly still had some legacy V2 compatibility cruft lingering from the V2 to V3 upgrade. We
> expected that they would have run through the typical IdP upgrade process, but perhaps that's not the case if
> we are in this situation.
It's not the case.
> I'm not sure it's a valid assumption, but we're presently assuming that well behaved SPs will generally roll
> with it and ignore the duplicate values. It hasn't seemed to have been an issue yet with the folks that have
> tested, though it has been noted by some of them.
I would not expect most Shibboleth SPs to just ignore them. They'd start seeing duplicate values and probably won't have application code equipped to deal with it.
> So I think we're at the point where we are attempting to streamline this aspect of the configuration to "fix"
> these duplicate attribute values since that would provide us with more confidence in backwards compatibility
> for perhaps less well-behaved SPs. Any pointers to references on how to get us to where the upgrade to V4
> should have left us would be welcomed.
The registry feature documentation covers how it all works and how to change the behavior. As with any service, the configurations it loads are in services.xml and a new install of 4.x will contain the resource collection for the registry so it can be edited. Remove the default rules from it and the duplicates will go away.
-- Scott
More information about the users
mailing list