Releasing the same attribute with different friendly names?
Cantor, Scott
cantor.2 at osu.edu
Mon Jan 23 21:01:18 UTC 2023
> ln my attribute-resolver, both lastname and sn come from the same LDAP
> attribute and both have a name defined as "urn:oid:2.5.4.4", but have different
> friendly names.
That isn't supported. It's only working by accident, a bug was fixed to prevent it from creating separate SAML Attributes with the same name anyway and that isn't getting "unfixed". It should have been doing that all along.
> Can anyone think of why this would be necessary? Is there a case where the SP
> cares what the friendlyname is?
Are there such SPs? Yes. That doesn't make it something you should tolerate, and practically speaking we made it impossible to do what you're doing, so...that's just how it is. It was fixed in 4.2.
-- Scott
More information about the users
mailing list