saml proxying scoped attributes...best practice
Cantor, Scott
cantor.2 at osu.edu
Wed Nov 13 00:41:10 UTC 2024
One other thing to bear in mind, and perhaps this has changed, but in the days that I ran a globally federated service, the EU tended NOT to allow release of EPPN, all we could get was (at that time) the targeted/pairwise NameID in SAML, so it was opaque and exceedingly ugly to use/handle.
That might have changed, or you may not care about global/non-US IdPs of course.
-- Scott
More information about the users
mailing list