nameID mutiple activationCondition per SP based on different src Attribute
Michael Grady
mgrady at unicon.net
Mon Sep 19 19:28:38 UTC 2022
> - Just to avoid "mistakes", in can be useful to define in your resolver "specific NameiD attributes", e.g.
> - define NameIDuid as based on your 'uid' attribute
> - with no encoders
> - when you want uid to be used as the source of the NameID value, release that NameIDuid attribute to the service (in the filter), and base your NameID format rules in sami-nameid.xml on those NameID-specific attributes
>
Of course, you do not have to define these "new' attributes, you can use your already defined ones (uid, EPPN, mail, etc.). But if you end up getting a long enough list of potential attributes that you want to use as the source of the value, these special purpose attribute definitions can keep it easier to not make a "mistake" and have the rule use an attribute value you did not want it to.
--
Michael A. Grady
IAM Architect, Unicon, Inc.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20220919/f473332e/attachment.htm>
More information about the users
mailing list