<div dir="ltr">Thanks, your particularly hostile response--with supporting evidence--will give me the capital I need to convince management we need to fix this.<div><br></div><div>Chris</div></div><div class="gmail_extra">
<br><br><div class="gmail_quote">On Tue, Jun 24, 2014 at 9:38 AM, Peter Schober <span dir="ltr">&lt;<a href="mailto:peter.schober@univie.ac.at" target="_blank">peter.schober@univie.ac.at</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
* Christopher Peters &lt;<a href="mailto:cjpeters@uci.edu">cjpeters@uci.edu</a>&gt; [2014-06-24 18:20]:<br>
<div class="">&gt; 1)  Is it wrong to have two encoders on an attribute?  It serves the<br>
&gt; purpose we had of matching the name no matter which scheme the SP chose.<br>
&gt;  And it didn&#39;t seem to me that URN:MACE or OID formats were specific to a<br>
</div>&gt; particular protocol [...]<br>
<br>
It is (wrong) and they are (protocol specific): The use of legacy<br>
names is specifically ruled our for use within SAML2, cf. 3.2. of<br>
<a href="http://macedir.org/docs/internet2-mace-dir-saml-attributes-latest.pdf" target="_blank">http://macedir.org/docs/internet2-mace-dir-saml-attributes-latest.pdf</a><br>
<div class=""><br>
&gt; 2) Is there an easy way--either on the IDP side or SP side--to filter down<br>
&gt; to a single encoding?<br>
<br>
</div>Use the software&#39;s default configuration? That will release the SAML1<br>
naming convention for SAML1 protocol messages, and the SAML2 naming<br>
convention for SAML2 protocol messages.<br>
<div class=""><br>
&gt; What would really make my life simpler is an improvement to the SP code<br>
&gt; that took the attributes and when it saw &quot;12345;12345&quot; just returned<br>
&gt; &quot;12345&quot;.  The classic array dupe reduction.  But I&#39;m not looking for an<br>
&gt; improvement to Shibboleth to solve my issue.  Maybe there&#39;s some way to<br>
&gt; accomplish this already that I don&#39;t know?<br>
&gt;<br>
&gt; In the end, if there&#39;s not a simple fix my larger scale resolution will be<br>
&gt; to split the encodings into two separate attributes on the IDP side and<br>
&gt; release the right ones at the right time, but that&#39;s confusing to<br>
&gt; maintain.<br>
<br>
</div>&quot;Do nothing&quot; seems to work just fine for every other IDP deployment on<br>
the planet?<br>
-peter<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div><br><br clear="all"><div><br></div>-- <br><div dir="ltr">







<font face="arial black, sans-serif">Chris Peters</font><br>Middleware Services Developer<br>Office of Information Technology - NSP<br>(949) 824-6845<br><a href="mailto:cjpeters@uci.edu" target="_blank">cjpeters@uci.edu</a><br>
</div>
</div>