<html><head><meta http-equiv="Content-Type" content="text/html charset=windows-1252"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;">We have gone to great lengths to make the string in ePPN also be a routable email address<div>(originally mailAlternateAddress within an LDAP directory used for mail routing by the mail</div><div>service, subsequently pushed as aliases to GAE) but it ain’t simple and requires ongoing </div><div>effort not to “break” as totally separate business processes and governance make changes </div><div>in institutional email services and assigned addresses.<div><br></div><div><div>If starting identity management or institutional email from scratch, I would like a policy </div><div>requiring an unchanging identifier that would be used for ePPN and a persistent </div><div>routable email address. I would also expect a lot of resistance from several quarters</div><div>(in principal, because it represents a constraint on their authority for unilateral decisions).</div><div><br></div><div>David Bantz</div><div><br></div><div><div><div><div>On Wed, 4 Jun 2014, at 10:07 , David Langenberg <<a href="mailto:davel@uchicago.edu">davel@uchicago.edu</a>> wrote:</div><br class="Apple-interchange-newline"><blockquote type="cite">I wouldn't say eppn == mail, but would suggest that eppn is a routable address for the user<span></span>. <div><br></div><div>Dave <br><br>On Wednesday, June 4, 2014, Tom Scavo <<a href="mailto:trscavo@gmail.com">trscavo@gmail.com</a>> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">On Wed, Jun 4, 2014 at 1:40 PM, David Bantz <<a href="javascript:;" onclick="_e(event, 'cvml', 'dabantz@alaska.edu')">dabantz@alaska.edu</a>> wrote:<br>
><br>
> On Wed, 4 Jun 2014, at 08:34 , Tom Scavo <<a href="javascript:;" onclick="_e(event, 'cvml', 'trscavo@gmail.com')">trscavo@gmail.com</a>> wrote:<br>
><br>
> We've talked about tagging IdPs with<br>
> various marks for best practices, but I really think we need a "package"<br>
> of practices to capture into a mark of some kind.<br>
><br>
> Something like this? <a href="https://spaces.internet2.edu/x/x4HYAg" target="_blank">https://spaces.internet2.edu/x/x4HYAg</a><br>
><br>
> which states in part:<br>
><br>
> "Support at least the following user attributes:...mail (== ePPN)"<br>
><br>
> sigh….<br>
<br>
You're the third person to react like that :-) so I may want to modify<br>
that. The idea is: If you were building your IdM from scratch, it<br>
would be advisable to define your email addresses and ePPNs to be the<br>
same. This may be the wrong list but...do folks agree with that?<br>
<br>
Tom<br>
--<br>
To unsubscribe from this list send an email to <a href="javascript:;" onclick="_e(event, 'cvml', 'users-unsubscribe@shibboleth.net')">users-unsubscribe@shibboleth.net</a></blockquote></div><br><br>-- <br>
David Langenberg<div>Identity & Access Management</div><div>The University of Chicago</div><br>
--<br>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a></blockquote></div><br></div></div></div></div></body></html>