saml proxying scoped attributes...best practice
Paul B. Henson
henson at acm.org
Wed Nov 13 03:56:14 UTC 2024
On 11/12/2024 4:38 PM, Cantor, Scott via users wrote:
>> I'm not sure how often this happens in practice, but if an
>> upstream IdP re-uses the same identifier (EPPN) for 2 different
>> users, I don’t know if I care too much.
>
> Well, I guess I can't really argue that. To me, it's pretty major
> and disqualifying. I think most people at least lean toward my take
> on that issue.
Somebody once "reused" my wife's Social Security number. Indeed, the
service that accepted it didn't care too much. My wife certainly wasn't
a happy camper on the other hand.
>> I also don’t care too much about length limits or character set.
>> If either of those become an issue, we can simply not allow
>> authentication with that IdP anymore.
>
> That's not so casual a decision if actual users are involved by that
> point.
[...]
>> I think maybe the SAML community is becoming to overly concerned
>> with these edge cases and the result is more spec changes/
>> requirements that hider interoperability.
>
> I obviously have a very different view of that. System design to me
> is entirely about edge cases.
Wow, I hope I am never in the position of having to use a service
designed and managed by the OP 8-/.
More information about the users
mailing list