<div dir="ltr">+1</div><div class="gmail_extra"><br><div class="gmail_quote">On Thu, Feb 23, 2017 at 10:13 AM, Domingues, Michael D <span dir="ltr"><<a href="mailto:michael-domingues@uiowa.edu" target="_blank">michael-domingues@uiowa.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">





<div lang="EN-US" link="#0563C1" vlink="#954F72">

<div id="m_7972372412319470147divtagdefaultwrapper" style="font-size:11pt;color:#000000;font-family:Calibri,Arial,Helvetica,sans-serif" dir="ltr">
<p>If at all possible, I'd strongly suggest to the vendor that what they're doing is horribly backwards.</p>
<p><br>
</p>
<p>That said, in situations such as these if I have no other choice, my approach has been to create a separate AttributeDefinition entry (with an id like "uid_SillyVendorNameHere") from the same source attribute, with whatever non-standard tweaks they vehemently
 insist upon, and release that to them instead.</p>
<p><br>
</p>
<p>You absolutely won't want to change your working definition.<br>
</p>
<p><br>
</p>
<p>Michael<br>
</p>
</div>
<hr style="display:inline-block;width:98%">
<div id="m_7972372412319470147divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> users <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a>> on behalf of XiaoXia Dong <<a href="mailto:x-dong@northwestern.edu" target="_blank">x-dong@northwestern.edu</a>><br>
<b>Sent:</b> Thursday, February 23, 2017 1:09:59 PM<br>
<b>To:</b> Shib Users<br>
<b>Cc:</b> Phil Tracy<br>
<b>Subject:</b> change definition of uid name and friendlyname</font>
<div> </div>
</div><div><div class="h5">
<div>
<div class="m_7972372412319470147WordSection1">
<p class="MsoNormal">Hello Shib Experts,<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">We have a vendor which does not work with the out of box definition of uid,<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">Here is the original one:<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">   <resolver:AttributeDefinition xsi:type="ad:Simple" id="uid" sourceAttributeID="uid"><u></u><u></u></p>
<p class="MsoNormal">        <resolver:Dependency ref="myLDAP" /><u></u><u></u></p>
<p class="MsoNormal">        <resolver:AttributeEncoder xsi:type="enc:SAML1String" name="urn:mace:dir:attribute-<wbr>def:uid" /><u></u><u></u></p>
<p class="MsoNormal">        <resolver:AttributeEncoder xsi:type="enc:SAML2String" name="urn:oid:0.9.2342.<wbr>19200300.100.1.1" friendlyName="uid" /><u></u><u></u></p>
<p class="MsoNormal">    </resolver:<wbr>AttributeDefinition><u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">In order to make this particular app work, I need to swap the name and friendlyName of uid,
<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal"> <resolver:AttributeDefinition xsi:type="ad:Simple" id="uid" sourceAttributeID="uid"><u></u><u></u></p>
<p class="MsoNormal">        <resolver:Dependency ref="myLDAP" /><u></u><u></u></p>
<p class="MsoNormal">        <resolver:AttributeEncoder xsi:type="enc:SAML1String" name="urn:mace:dir:attribute-<wbr>def:uid" /><u></u><u></u></p>
<p class="MsoNormal">        <resolver:AttributeEncoder xsi:type="enc:SAML2String" name="uid" friendlyName="urn:oid:0.9.<wbr>2342.19200300.100.1.1" /><u></u><u></u></p>
<p class="MsoNormal">    </resolver:<wbr>AttributeDefinition><u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">I realized that this is a global change and it could potentially break some other applications. I like to get opinions from shib experts how risky this change is and whether it is a safe change from SAML2.<u></u><u></u></p>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal">Thank you.<u></u><u></u></p>
</div>
</div>
</div></div></div>

<br>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br></blockquote></div><br></div>