<div dir="ltr"><br><div class="gmail_extra"><br><br><div class="gmail_quote">On Sat, Sep 7, 2013 at 9:55 AM, Bryan E. Wooten <span dir="ltr">&lt;<a href="mailto:bryan.wooten@utah.edu" target="_blank">bryan.wooten@utah.edu</a>&gt;</span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div class="im">&gt;<br>
&gt;<br>
&gt;<br>
&gt;That is normal. Shibboleth doesn&#39;t care anything about eduPerson, those<br>
&gt;are just defaults.<br>
&gt;<br>
&gt;Curious to hear what those attributes they want are though, in my<br>
&gt;experience there isn&#39;t much that isn&#39;t usually mappable to eduPerson or<br>
&gt;other standard LDAP schemas that is commonly requested.<br>
&gt;<br>
&gt;-- Scott<br>
<br>
</div>We get requests for all kinds of attributes, some reasonable some make you<br>
scratch your head. Many want things like dept id or or org id or<br>
enrollment in a particular class / major or &quot;chart field&quot; (for billing<br>
purposes). We have one app that needs to know whether or not a student<br>
lives in campus housing.<br>
<br>
Then there is the request by one dept to have a student&#39;s complete<br>
historical record of majors / enrollments available via LDAPŠ.<br></blockquote><div><br></div><div>Here&#39;s where your Grouper installation comes to your rescue.  Some of the time, yes, their app needs the attribute and in those cases we do create and release the attributes.  However, often when you engage them in a dialog about why they need &quot;enrolled in HIST-247&quot; attribute it boils down to them just needing a flag that says &quot;authorized for app X&quot; and all the various attributes they&#39;re requesting are really so they can make the computation of &quot;authorized for app X&quot;.   The paradigm we follow over here is to create a group-structure for that app and then utilize grouper to build the &quot;authorized for app X&quot; group along with app-specific permission groups.  We then push those to LDAP &amp; have a shib shib just pass isMemberOf over.  In this example I&#39;d have a group &quot;uc:applications:history:authorized&quot; and the group &quot;uc:reference:students:enrollment:autumn2013:history:247&quot; a member of :authorized.  </div>
<div><br></div><div>Dave</div><div><br></div></div>-- <br>David Langenberg<div>Identity &amp; Access Management</div><div>The University of Chicago</div>
</div></div>