<html><head><meta http-equiv="Content-Type" content="text/html charset=windows-1252"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;">We have gone to great lengths to make the string in ePPN also be a routable email address<div>(originally mailAlternateAddress within an LDAP directory used for mail routing by the mail</div><div>service, &nbsp;subsequently pushed as aliases to GAE) but it ain’t simple and requires ongoing&nbsp;</div><div>effort not to “break” as totally separate business processes and governance make changes&nbsp;</div><div>in institutional email services and assigned addresses.<div><br></div><div><div>If starting identity management or institutional email from scratch, I would like a policy&nbsp;</div><div>requiring an unchanging identifier that would be used for ePPN and a persistent&nbsp;</div><div>routable email address. &nbsp;I would also expect a lot of resistance from several quarters</div><div>(in principal, because it represents a constraint on their authority for unilateral decisions).</div><div><br></div><div>David Bantz</div><div><br></div><div><div><div><div>On Wed, 4 Jun 2014, at 10:07 , David Langenberg &lt;<a href="mailto:davel@uchicago.edu">davel@uchicago.edu</a>&gt; wrote:</div><br class="Apple-interchange-newline"><blockquote type="cite">I wouldn't say eppn == mail, but would suggest that eppn is a routable address for the user<span></span>.&nbsp;<div><br></div><div>Dave&nbsp;<br><br>On Wednesday, June 4, 2014, Tom Scavo &lt;<a href="mailto:trscavo@gmail.com">trscavo@gmail.com</a>&gt; wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">On Wed, Jun 4, 2014 at 1:40 PM, David Bantz &lt;<a href="javascript:;" onclick="_e(event, 'cvml', 'dabantz@alaska.edu')">dabantz@alaska.edu</a>&gt; wrote:<br>

&gt;<br>
&gt; On Wed, 4 Jun 2014, at 08:34 , Tom Scavo &lt;<a href="javascript:;" onclick="_e(event, 'cvml', 'trscavo@gmail.com')">trscavo@gmail.com</a>&gt; wrote:<br>
&gt;<br>
&gt; We've talked about tagging IdPs with<br>
&gt; various marks for best practices, but I really think we need a "package"<br>
&gt; of practices to capture into a mark of some kind.<br>
&gt;<br>
&gt; Something like this? <a href="https://spaces.internet2.edu/x/x4HYAg" target="_blank">https://spaces.internet2.edu/x/x4HYAg</a><br>
&gt;<br>
&gt; which states in part:<br>
&gt;<br>
&gt; "Support at least the following user attributes:...mail (== ePPN)"<br>
&gt;<br>
&gt; sigh….<br>
<br>
You're the third person to react like that :-) so I may want to modify<br>
that. The idea is: If you were building your IdM from scratch, it<br>
would be advisable to define your email addresses and ePPNs to be the<br>
same. This may be the wrong list but...do folks agree with that?<br>
<br>
Tom<br>
--<br>
To unsubscribe from this list send an email to <a href="javascript:;" onclick="_e(event, 'cvml', 'users-unsubscribe@shibboleth.net')">users-unsubscribe@shibboleth.net</a></blockquote></div><br><br>-- <br>
David Langenberg<div>Identity &amp; Access Management</div><div>The University of Chicago</div><br>
--<br>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a></blockquote></div><br></div></div></div></div></body></html>