<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<style type="text/css" style="display:none;"><!-- P {margin-top:0;margin-bottom:0;} --></style>
</head>
<body dir="ltr">
<div id="divtagdefaultwrapper" style="font-size:12pt;color:#000000;font-family:Calibri,Helvetica,sans-serif;" dir="ltr">
<p style="margin-top:0;margin-bottom:0">Baron,</p>
<p style="margin-top:0;margin-bottom:0"><br>
</p>
<p style="margin-top:0;margin-bottom:0">All the SAML names on the wire are totally independent from those used internally by the IdP. Maybe you could try following your traditional strategy and be sure to set friendlyName="mail" (or whatever else they want)
on the relevant attribute encoder.</p>
<p style="margin-top:0;margin-bottom:0"><br>
</p>
<p style="margin-top:0;margin-bottom:0">Take care,</p>
<p style="margin-top:0;margin-bottom:0">Nate.</p>
</div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Baron Fujimoto <baron@hawaii.edu><br>
<b>Sent:</b> Monday, June 18, 2018 2:25:10 PM<br>
<b>To:</b> Shib Users<br>
<b>Subject:</b> alternate attribute names</font>
<div> </div>
</div>
<div class="BodyFragment"><font size="2"><span style="font-size:11pt;">
<div class="PlainText">We are working with an SP (ArcGIS) who in unable to properly handle 'mail'<br>
as a potentially multivalued attibute. Normally we would offer an<br>
alternate attribute we have defined with id=uhEmail which we guarantee to<br>
to be single-valued and encode with the same OID as the sandard mail<br>
attribute where this is an issue. However, this SP also insists that this<br>
attribute they require be named 'mail'.<br>
<br>
Is there a way to remap a defined attribute's name (id) in an attribute<br>
filter policy, or conditionally specify its source attribute in an<br>
attribute definition based on the requesting entityID in the attribute<br>
resolver? How can we release our single-valued uhEmail attribute to this<br>
SP as 'mail' without disrupting our existing definition or release of<br>
'mail' for other SPs already in use? What's the recommended way to handle<br>
this?<br>
<br>
-- <br>
Baron Fujimoto <baron@hawaii.edu> :: UH Information Technology Services<br>
minutas cantorum, minutas balorum, minutas carboratum desendus pantorum<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg">
https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font></div>
</body>
</html>