saml proxying scoped attributes...best practice

Paul B. Henson henson at acm.org
Wed Nov 13 03:56:14 UTC 2024


On 11/12/2024 4:38 PM, Cantor, Scott via users wrote:

>> I'm not sure how often this happens in practice, but if an 
>> upstream IdP re-uses the same identifier (EPPN) for 2 different
>> users, I don’t know if I care too much.
> 
> Well, I guess I can't really argue that. To me, it's pretty major
> and disqualifying. I think most people at least lean toward my take
> on that issue.

Somebody once "reused" my wife's Social Security number. Indeed, the 
service that accepted it didn't care too much. My wife certainly wasn't 
a happy camper on the other hand.

>> I also don’t care too much about length limits or character set.
>> If either of those become an issue, we can simply not allow
>> authentication with that IdP anymore.
> 
> That's not so casual a decision if actual users are involved by that
> point.
[...]
>> I think maybe the SAML community is becoming to overly concerned
>> with these edge cases and the result is more spec changes/
>> requirements that hider interoperability.
> 
> I obviously have a very different view of that. System design to me
> is entirely about edge cases.

Wow, I hope I am never in the position of having to use a service 
designed and managed by the OP 8-/.


More information about the users mailing list