<div dir="ltr">Thanks David,  I had thought about that... though I wasn't sure how our vendor would/could handle .. it is something to consider. ... the IDs are unique ..so it's a definite maybe.<div><br clear="all"><div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div><div></div><div><br></div><div>Brad Mathis</div><div>IT Principal Systems Analyst</div><div>Infrastructure Services - Applications<br></div><div>Pima Community College<br></div><div>520.206.4826<br></div><div><a href="mailto:bmathis@pima.edu" target="_blank">bmathis@pima.edu</a></div></div><div><br></div><div><img src="https://docs.google.com/a/pima.edu/uc?id=0B4QEFWYNTFJATTZySzROc0JISEk&export=download" width="200" height="150"><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div></div></div></div></div></div></div></div></div></div></div></div></div></div><br></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Wed, Jul 3, 2019 at 12:02 PM IAM David Bantz <<a href="mailto:dabantz@alaska.edu">dabantz@alaska.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr">To keep your ePPNs scoped @<a href="http://pima.edu" target="_blank">pima.edu</a> :<div><br></div><div>Assuming staff & students have unique non-colliding IDs in a single name-space (which seems likely if both groups authenticate by providing those IDs):<div>Assign ePPN of <a href="mailto:student1@pima.edu" target="_blank">student1@pima.edu</a> [instead of the email address] in attribute-resolver.<br>That does presume the vendor does not rely on the scoped principal name doubling as a valid email address (alas some do).</div><div><br></div><div>David Bantz</div><div>UA OIT IAM</div><div><br></div></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Wed, Jul 3, 2019 at 9:45 AM Mathis, Bradley <<a href="mailto:bmathis@pima.edu" target="_blank">bmathis@pima.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr"><div dir="ltr"><div><div>First off,  thank you for your time in reading this for any patience you can have with my lack of understanding how metadata works or is used.</div><div><br></div><div>We have a helpdesk/ticket tracking system that we are using.  We are the idp and they are the SP and they/we are using InCommon in this case for our metadata repository.</div><div><br></div><div>We are sending the eduPersonPrincipalName along with a few other basic attributes at login.... though I'm pretty sure the eduPersonPrincipalName is what is being</div><div>used to actually login/authorize access.  </div><div><br></div><div>Currently all our College staff are able to login and use the system.  For example my eduPersonPrincipalName value is e.g.  <a href="mailto:bmathis@pima.edu" target="_blank">bmathis@pima.edu</a> this works fine.</div><div><br></div><div>We now have some who want to add students to the system.  When they attempt login they are denied access (actually it looks like it goes into a loop).  The student eduPersonPrincipalName value is using a subdomain like this <a href="mailto:student1@mail.pima.edu" target="_blank">student1@mail.pima.edu</a>.</div><div><br></div><div>We have asked the vendor to allow users that have eduPersonPrincipalName value of <a href="mailto:username@mail.pima.edu" target="_blank">username@mail.pima.edu</a> to be valid users of the system.</div><div><br></div><div>Their response was that we would need to change our metadata with inCommon to allow the new scope... I assume they mean add <a href="http://mail.pima.edu" target="_blank">mail.pima.edu</a> to the scope ...</div><div>I do see we have a scope in our metadata for <a href="http://pima.edu" target="_blank">pima.edu</a> .... which is correct.   Due to my ignorance I'm not certain if what they are asking is valid .... I have read some of the </div><div>Incommon documentation about it ... at <a href="https://spaces.at.internet2.edu/display/InCFederation/Scope+in+Metadata" target="_blank">https://spaces.at.internet2.edu/display/InCFederation/Scope+in+Metadata</a>  but I'm still processing it.  It appears I can add another scope but it will most certain generate manaul vetting if I do.</div><div><br></div><div>I guess I just want to make sure..... is this really needed to resolve our issue? </div><div><br></div><div>We are sending them the correct value for the user in the eduPersonPrincipalName I'm not understanding why our metadata needs the scope added... why can't they userthe </div><div>eduPersonPrincipalName we send them.</div><div><br></div><div>I figure they really know what they are talking about or .. they might be as uneducated about it as I am :-)</div><div><br></div><div>Thanks for any feedback you have.</div></div><div><br></div><div><br></div><div><br></div><div><div dir="ltr" class="gmail-m_-5355872383682822582gmail-m_467126223204987759gmail_signature"><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div><div>Brad Mathis</div><div>IT Principal Systems Analyst</div><div>Infrastructure Services - Applications<br></div><div>Pima Community College<br></div><div>520.206.4826<br></div><div><a href="mailto:bmathis@pima.edu" target="_blank">bmathis@pima.edu</a></div></div><div><br></div><div><img src="https://docs.google.com/a/pima.edu/uc?id=0B4QEFWYNTFJATTZySzROc0JISEk&export=download" width="200" height="150"><br></div><div><br></div><div><br></div><div><br></div><div><br></div><div><br></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a></blockquote></div>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a></blockquote></div>