<div dir="ltr"><div><div><div>We are in the middle of deploying IU's Kumo application. Without getting into what Kumo is, their SP needs to consume an attribute that matches our Active Directory userPrincipleName. However, because AD is not our identity store for shibb, and AD doesn't own the <a href="http://uncg.edu">uncg.edu</a> namespace, eppn != userPrincipleName. I'm also not too interested in storing AD UPN's in our LDAP. So what I would like to do is be able to create a custom attribute by taking our username (cn) and simply append a static string "@<a href="http://campus.uncg.edu">campus.uncg.edu</a>" matching our AD domain to form an representation of our AD UPN and release this to Kumo.<br><br></div>I'm not very versed with attribute transformations, but I imagine this one isn't too difficult, however I could use some guidance from the more SAML savy in what an attribute definition for something like this might look like. IU recommends we name this custom attribute "<a href="https://schemas.uits.iu.edu/CloudStorage/Identity/UPN">https://schemas.uits.iu.edu/CloudStorage/Identity/UPN</a>"<br><br></div>Thanks<br></div>-Rob<br><div><div><div><div><br clear="all"><div><br>-- <br><div class="gmail_signature"><div dir="ltr"><div>Robert W. Gorrell<br>Systems Architect, Identity and Access Management </div>
<div>University of NC at Greensboro<br><span style="white-space:nowrap">336-334-5954</span><br>PGP Key ID B36DB0CA<br></div></div></div>
</div></div></div></div></div></div>