<div dir="ltr"><div><div>Thanks! That clears some bits up that were keeping me up :)<br><br></div>So on longer term -- if we wish to leverage persistence ID (i.e. unique to the user per IdP/SP combination) --- where available both as SAML2String and as a SAML2NameID -- what is the best configuration option?<br></div><div><br></div><div>Ideally the value would be UUID off the bat.</div><div><br></div><div>The SAML2String version will be a new AttributeDefinition ID (internal to our instituition). On another note -- eduPersonTargetedID will never be used by us.<br></div><div><br></div></div><div class="gmail_extra"><br><div class="gmail_quote">On Sun, Jan 28, 2018 at 4:59 AM, Peter Schober <span dir="ltr"><<a href="mailto:peter.schober@univie.ac.at" target="_blank">peter.schober@univie.ac.at</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">* Hugo Slavia <<a href="mailto:hugoslavia101@gmail.com">hugoslavia101@gmail.com</a>> [2018-01-28 05:18]:<br>
<span class="">> On a separate note -- there appears to be some sadness over at my<br>
> institution that EPTI are deprecated -- what is the backstory behind<br>
> this?<br>
<br>
</span>Don't worry, the attribute form of eduPersonTargetID is being<br>
deprecated together with what should have been its replacement in<br>
SAML2.0 (the NameID -- i.e., the attribute /value/ of an<br>
eduPersonTargetID attribute -- sent in the SAML Assertion's Subject),<br>
so *both* are on the way out.<br>
Together with eduPersonUniqueID and (possibly) eduPersonPrincipalName.<br>
<br>
See section 2.1 of the<br>
<br>
  SAML V2.0 Subject Identifier Attributes Profile<br>
  <a href="https://wiki.oasis-open.org/security/SAMLSubjectIDAttr" rel="noreferrer" target="_blank">https://wiki.oasis-open.org/<wbr>security/SAMLSubjectIDAttr</a><br>
<br>
Some background can also be found in this (out of date) write-up in<br>
the wiki:<br>
<br>
  <a href="https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPTargetedID" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/<wbr>confluence/display/SHIB2/<wbr>NativeSPTargetedID</a><br>
<br>
You'll note that the "botched" version (also called "broken", "a bug<br>
and a mistake" in that text and comments) is what the new Subject-ID<br>
(spec linked to above) will look like. So we've come full circle on<br>
this.<br>
<span class="HOEnZb"><font color="#888888"><br>
-peter<br>
</font></span><div class="HOEnZb"><div class="h5">--<br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/<wbr>confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br>
</div></div></blockquote></div><br></div>