[EXT] non-conforming values of eduPersonAffiliation

IAM David Bantz dabantz at alaska.edu
Tue Aug 26 01:01:30 UTC 2025


Thanks Scott,

As it happens, eduPersonEntitlement is exactly what I proposed in the first
place; and of course I could build and release an appropriate ePE in the
IdP but only if I have the supervisor value available to me in the
directory/attribute store, and the only option offered to me (unless I make
a stand) is for HR to put in into eduPersonAffiliation in the directory.

I guess I could get the 'supplemented' ePA values, create the entitlement
if the 'supervisor' value is there, and then remove any non-conforming
values so the ePA as released by my IdP remains correct. I guess....

db

On Mon, Aug 25, 2025 at 4:33 PM Cantor, Scott <cantor.2 at osu.edu> wrote:

> > To be more explicit, the constraint is HR's population of
> > 'supervisor' into the directory that is the issue: they already
> > populate conforming ePA values and can add the
> > 'supervisor' value as part of the routine sync to the record
> > of users who are supervisors, but they do NOT want to
> > revise or add a new process to populate the value to a
> > different attribute in AD.
>
> It's your directory. It doesn't follow that you have to produce such an
> Attribute out of a SAML IdP. Just turn it into an entitlement.
>
> -- Scott
>
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20250825/854826c0/attachment.htm>


More information about the users mailing list