saml proxying scoped attributes...best practice

Cantor, Scott cantor.2 at osu.edu
Wed Nov 13 00:41:10 UTC 2024


One other thing to bear in mind, and perhaps this has changed, but in the days that I ran a globally federated service, the EU tended NOT to allow release of EPPN, all we could get was (at that time) the targeted/pairwise NameID in SAML, so it was opaque and exceedingly ugly to use/handle.

That might have changed, or you may not care about global/non-US IdPs of course.

-- Scott




More information about the users mailing list