<div dir="ltr"><span style="font-size:small;text-decoration-style:initial;text-decoration-color:initial;float:none;display:inline">Thanks, Scott. </span><br style="font-size:small;text-decoration-style:initial;text-decoration-color:initial"><span style="font-size:small;text-decoration-style:initial;text-decoration-color:initial;float:none;display:inline">Seems like my customer rejected SP's requirement of 'unspecified' and hopefully SP will configure their configurations for better type of attributes.</span><br></div><br><div class="gmail_quote"><div dir="ltr">On Thu, Jul 12, 2018 at 11:43 AM Cantor, Scott <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">> I have a quick question.. what's the future plan of you guys for supporting<br>
> 'unspecified' type nameID format?<br>
<br>
We support it as much as it's possible to support it without violating the bounds of common sense.<br>
<br>
> I have done some overriding to support 'unspecified type' nameID format (<br>
> thanks to your doc ) for couple of my customers because their SP made it a<br>
> 'mandatory' item.<br>
<br>
I'm happy to learn which SP that might be and either prove them wrong through personal experience, or document that it exists. Enumerating them is useful (as is shaming them).<br>
<br>
To be clear, "I don't care" is a common cloud perspective, no matter how misguided it is. That's not the same as "requiring unspecified", and virtually all cases where people claim it's required are the former, not the latter.<br>
<br>
> Pardon me if I miss any doc/wiki on 'future plan of Shibboleth for unspecified<br>
> type nameID format' but if anyone of you can just share a hint, will be helpful<br>
> for me to request my customer to move for a proper nameID format ( i.e.<br>
> emailAddress ) instead of unspecified type.<br>
<br>
There is no reason to use it. It should never have been in the standard. Would you define an LDAP attribute called "unspecified"? Of course not. It was, plainly, a mistake and I'm not far from filing an errata on it, honestly, because of the outrageous amount of time it costs everybody, particularly me.<br>
<br>
If you want to know what we think in general, NameIDs should be omitted, or transient, only and never used for persistent identification of users. Our proposed approach is now drafted [1] and waiting (and waiting and waiting) for final approval.<br>
<br>
-- Scott<br>
<br>
[1] <a href="https://wiki.oasis-open.org/security/SAMLSubjectIDAttr" rel="noreferrer" target="_blank">https://wiki.oasis-open.org/security/SAMLSubjectIDAttr</a><br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div><br clear="all"><div><br></div>-- <br><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature">Best,<br>Zico</div>