<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">
Eric,
<div class=""><br class="">
</div>
<div class="">They'll correct me if I'm wrong, but I believe the functional difference is that the IdP has a few special operations it can perform if it knows an attribute is scoped.  This largely dates back to the very early days of Shibboleth, when Scope
 was sent as a separate attribute in the actual Attribute on the wire.  That blew up many implementations, so the default was changed to
<a href="mailto:ndk@calstate.edu" class="">ndk@calstate.edu</a>.</div>
<div class=""><br class="">
</div>
<div class="">You can find some relics of this here with "attribute" versus "inline".</div>
<div class=""><br class="">
</div>
<div class=""><a href="https://wiki.shibboleth.net/confluence/display/IDP30/SAML2ScopedStringEncoder" class="">https://wiki.shibboleth.net/confluence/display/IDP30/SAML2ScopedStringEncoder</a></div>
<div class=""><br class="">
</div>
<div class="">As long as you're not doing anything in the IdP that requires operation on a scoped attribute and you're not releasing scopes as an attribute(and I haven't seen that in... a long time), then I don't think there will be any practical difference.</div>
<div class=""><br class="">
</div>
<div class="">Ready for the beanbags,</div>
<div class="">Nate.<br class="">
<div class=""><br class="">
<div>
<blockquote type="cite" class="">
<div class="">On Jul 20, 2016, at 12:20 PM, Eric Goodman <<a href="mailto:Eric.Goodman@ucop.edu" class="">Eric.Goodman@ucop.edu</a>> wrote:</div>
<br class="Apple-interchange-newline">
<div class="">
<div class="WordSection1" style="page: WordSection1; font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px;">
<div style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;" class="">
So this is, I think, a very basic (and probably not operationally important) question:<o:p class=""></o:p></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;" class="">
<o:p class=""> </o:p></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;" class="">
What is the practical value of having a SAML type of SAMLnScopedString?<o:p class=""></o:p></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;" class="">
<o:p class=""> </o:p></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;" class="">
We noticed that one of our IdPs is resolving ePPN as an unscoped attribute, and we wanted to fix that. Then we realized: “hey, why isn’t this already broken?” At least one of our IdPs that resolves ePPN as a scoped string still expresses the attribute in assertions
 as an xsd:string with no formal Scope element.<o:p class=""></o:p></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;" class="">
<o:p class=""> </o:p></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;" class="">
The delivered attribute-policy file on the Shib SP defines a ScopingRules that disallows “@” in the attribute value. The delivered attribute-map file invokes the ScopedAttributeDecoder. I can only assume that the ScopedAttributeDecoder is basically splitting
 all flat string values into scoped attributes prior to applying the policy. FWIW, nothing in the formal definition of ePPN appears to declare it formally as a SAML Scoped String either, it’s just defined as a string that it is composed of a value and a scope
 separated by an “@”.<o:p class=""></o:p></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;" class="">
<o:p class=""> </o:p></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;" class="">
So if the scoped attributes are generally expressed as strings with implicit rules, and even the Shib IdP puts them (in at least some cases) on the wire without a specified scope, what’s the practical purpose of defining the attribute as SAML2ScopedString vs
 just calling it a string?<span class="Apple-converted-space"> </span><o:p class=""></o:p></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;" class="">
<o:p class=""> </o:p></div>
<div style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;" class="">
--- Eric<o:p class=""></o:p></div>
</div>
<span style="font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; float: none; display: inline !important;" class="">--<span class="Apple-converted-space"> </span></span><br style="font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px;" class="">
<span style="font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; float: none; display: inline !important;" class="">To
 unsubscribe from this list send an email to<span class="Apple-converted-space"> </span></span><a href="mailto:users-unsubscribe@shibboleth.net" style="color: purple; text-decoration: underline; font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px;" class="">users-unsubscribe@shibboleth.net</a></div>
</blockquote>
</div>
<br class="">
</div>
</div>
</body>
</html>