<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 14 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:blue;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:purple;
text-decoration:underline;}
span.EmailStyle17
{mso-style-type:personal-compose;
font-family:"Calibri","sans-serif";
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-family:"Calibri","sans-serif";}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal">So this is, I think, a very basic (and probably not operationally important) question:<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">What is the practical value of having a SAML type of SAMLnScopedString?<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">We noticed that one of our IdPs is resolving ePPN as an unscoped attribute, and we wanted to fix that. Then we realized: “hey, why isn’t this already broken?” At least one of our IdPs that resolves ePPN as a scoped string still expresses
the attribute in assertions as an xsd:string with no formal Scope element.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">The delivered attribute-policy file on the Shib SP defines a ScopingRules that disallows “@” in the attribute value. The delivered attribute-map file invokes the ScopedAttributeDecoder. I can only assume that the ScopedAttributeDecoder
is basically splitting all flat string values into scoped attributes prior to applying the policy. FWIW, nothing in the formal definition of ePPN appears to declare it formally as a SAML Scoped String either, it’s just defined as a string that it is composed
of a value and a scope separated by an “@”.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">So if the scoped attributes are generally expressed as strings with implicit rules, and even the Shib IdP puts them (in at least some cases) on the wire without a specified scope, what’s the practical purpose of defining the attribute as
SAML2ScopedString vs just calling it a string? <o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">--- Eric<o:p></o:p></p>
</div>
</body>
</html>