<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
font-size:11.0pt;
font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:blue;
text-decoration:underline;}
span.EmailStyle18
{mso-style-type:personal-reply;
font-family:"Calibri",sans-serif;
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple" style="word-wrap:break-word">
<div class="WordSection1">
<p class="MsoNormal">I would agree, Spencer, that you should stop listing eptid since it sounds like the Shibboleth IdP in the not-too-distant future will stop supporting a way to provide it. With that said, it’ll take some time for deployers to move to a version
of the IdP that no longer supports it, but to stop encouraging folks to send it in new integrations would make sense.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Thanks for confirming for me that there’s a relatively clean way to make this transition on the SP side.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Per Scott’s comment about <requestedAttribute>, I don’t know how widely used it is, but I know that we’re not the only school that releases requested attributes to InCommon participants. If we drop the eptid attribute definition, and since
InCommon doesn’t support an SP being able to signal their preferred name ID format in metadata, it sounds like we’re going to be breaking some things. Maybe the answer here is support for requested name ID format in InCommon metadata. But that’s not a topic
for this list.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Keith<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b>From:</b> users <users-bounces@shibboleth.net> <b>On Behalf Of
</b>Spencer Thomas<br>
<b>Sent:</b> Monday, July 26, 2021 10:16 AM<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Subject:</b> Re: Attribute definition type for eduPersonTargetedID?<o:p></o:p></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<p class="MsoNormal" style="margin-bottom:12.0pt">As the tech admin for an SP that can accept ePTID, I am just a little bit confused. We do not require either name format in our SP metadata, but one of our applications wants a “name ID” value. This is what
our support document says:<o:p></o:p></p>
<table class="MsoNormalTable" border="0" cellspacing="0" cellpadding="0" width="810" style="width:607.5pt;background:white;border-collapse:collapse">
<tbody>
<tr>
<td valign="top" style="border:solid #CCCCCC 1.0pt;padding:7.5pt 7.5pt 7.5pt 7.5pt">
<p class="MsoNormal" style="margin-top:7.5pt"><b><span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:black">Attribute Name<o:p></o:p></span></b></p>
</td>
<td valign="top" style="border:solid #CCCCCC 1.0pt;border-left:none;padding:7.5pt 7.5pt 7.5pt 7.5pt">
<p class="MsoNormal" style="margin-top:7.5pt"><b><span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:black">Description<o:p></o:p></span></b></p>
</td>
<td valign="top" style="border:solid #CCCCCC 1.0pt;border-left:none;padding:7.5pt 7.5pt 7.5pt 7.5pt">
<p class="MsoNormal" style="margin-top:7.5pt"><b><span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:black">Example<o:p></o:p></span></b></p>
</td>
</tr>
<tr>
<td valign="top" style="border:solid #CCCCCC 1.0pt;border-top:none;padding:7.5pt 7.5pt 7.5pt 7.5pt">
<p class="MsoNormal" style="margin-top:7.5pt"><span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:black">urn:oid:1.3.6.1.4.1.5923.1.1.1.10 or urn:oasis:names:tc:SAML:2.0:nameid-format:persistent (persistent-id) </span><b><span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:red">REQUIRED</span></b><span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:black"><o:p></o:p></span></p>
</td>
<td valign="top" style="border-top:none;border-left:none;border-bottom:solid #CCCCCC 1.0pt;border-right:solid #CCCCCC 1.0pt;padding:7.5pt 7.5pt 7.5pt 7.5pt">
<p class="MsoNormal" style="margin-top:7.5pt"><span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:black">Persistent identifier that provides Artstor (SP) with a unique identifier for the account holder<o:p></o:p></span></p>
</td>
<td valign="top" style="border-top:none;border-left:none;border-bottom:solid #CCCCCC 1.0pt;border-right:solid #CCCCCC 1.0pt;padding:7.5pt 7.5pt 7.5pt 7.5pt">
<p class="MsoNormal" style="margin-top:7.5pt"><span style="font-size:10.5pt;font-family:"Arial",sans-serif;color:black">URL of IdP!SP Entity ID! Unique Identifier<o:p></o:p></span></p>
</td>
</tr>
</tbody>
</table>
<p class="MsoNormal" style="margin-bottom:12.0pt"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-bottom:12.0pt">I see that the first one is eduPersonTargetedID). The second one appears to be specifying that we will accept NameID in that format (which could be written a little more clearly, I think).<o:p></o:p></p>
<p class="MsoNormal" style="margin-bottom:12.0pt">Our attribute-map.xml has these entries that map both to the same “friendly” name for further processing:<o:p></o:p></p>
<p class="MsoNormal" style="background:white"><span style="font-size:9.0pt;font-family:"Courier New";color:#080808"><</span><span style="font-size:9.0pt;font-family:"Courier New";color:#0033B3">Attribute
</span><span style="font-size:9.0pt;font-family:"Courier New";color:#174AD4">name</span><span style="font-size:9.0pt;font-family:"Courier New";color:#067D17">="urn:oid:1.3.6.1.4.1.5923.1.1.1.10"
</span><span style="font-size:9.0pt;font-family:"Courier New";color:#174AD4">id</span><span style="font-size:9.0pt;font-family:"Courier New";color:#067D17">="persistent-id"</span><span style="font-size:9.0pt;font-family:"Courier New";color:#080808">><br>
<</span><span style="font-size:9.0pt;font-family:"Courier New";color:#0033B3">AttributeDecoder
</span><span style="font-size:9.0pt;font-family:"Courier New";color:#871094">xsi</span><span style="font-size:9.0pt;font-family:"Courier New";color:#174AD4">:type</span><span style="font-size:9.0pt;font-family:"Courier New";color:#067D17">="NameIDAttributeDecoder"
</span><span style="font-size:9.0pt;font-family:"Courier New";color:#174AD4">formatter</span><span style="font-size:9.0pt;font-family:"Courier New";color:#067D17">="$NameQualifier!$SPNameQualifier!$Name"
</span><span style="font-size:9.0pt;font-family:"Courier New";color:#174AD4">defaultQualifiers</span><span style="font-size:9.0pt;font-family:"Courier New";color:#067D17">="true"</span><span style="font-size:9.0pt;font-family:"Courier New";color:#080808">/><br>
</</span><span style="font-size:9.0pt;font-family:"Courier New";color:#0033B3">Attribute</span><span style="font-size:9.0pt;font-family:"Courier New";color:#080808">><br>
</span><i><span style="font-size:9.0pt;font-family:"Courier New";color:#8C8C8C"><br>
</span></i><span style="font-size:9.0pt;font-family:"Courier New";color:#080808"><</span><span style="font-size:9.0pt;font-family:"Courier New";color:#0033B3">Attribute
</span><span style="font-size:9.0pt;font-family:"Courier New";color:#174AD4">name</span><span style="font-size:9.0pt;font-family:"Courier New";color:#067D17">="urn:oasis:names:tc:SAML:2.0:nameid-format:persistent"
</span><span style="font-size:9.0pt;font-family:"Courier New";color:#174AD4">id</span><span style="font-size:9.0pt;font-family:"Courier New";color:#067D17">="persistent-id"</span><span style="font-size:9.0pt;font-family:"Courier New";color:#080808">><br>
<</span><span style="font-size:9.0pt;font-family:"Courier New";color:#0033B3">AttributeDecoder
</span><span style="font-size:9.0pt;font-family:"Courier New";color:#871094">xsi</span><span style="font-size:9.0pt;font-family:"Courier New";color:#174AD4">:type</span><span style="font-size:9.0pt;font-family:"Courier New";color:#067D17">="NameIDAttributeDecoder"
</span><span style="font-size:9.0pt;font-family:"Courier New";color:#174AD4">formatter</span><span style="font-size:9.0pt;font-family:"Courier New";color:#067D17">="$NameQualifier!$SPNameQualifier!$Name"
</span><span style="font-size:9.0pt;font-family:"Courier New";color:#174AD4">defaultQualifiers</span><span style="font-size:9.0pt;font-family:"Courier New";color:#067D17">="true"</span><span style="font-size:9.0pt;font-family:"Courier New";color:#080808">/><br>
</</span><span style="font-size:9.0pt;font-family:"Courier New";color:#0033B3">Attribute</span><span style="font-size:9.0pt;font-family:"Courier New";color:#080808">><o:p></o:p></span></p>
<p class="MsoNormal" style="background:white"><o:p> </o:p></p>
<p class="MsoNormal" style="margin-bottom:12.0pt">From this conversation, I think we should stop listing ePTID in our support documentation, although we should continue to recognize it.<o:p></o:p></p>
<p class="MsoNormal" style="margin-bottom:12.0pt">From Scott’s comments, it would seem that we don’t need to make any changes to our metadata.<o:p></o:p></p>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">-- <o:p></o:p></p>
<div>
<p class="MsoNormal"><b><span style="color:black">Spencer Thomas<br>
</span></b><span style="color:black">Technical Architect <b>/</b> JSTOR and Artstor<br>
<a href="https://urldefense.com/v3/__https:/www.ithaka.org/__;!!DZ3fjg!rVkG_uJoE9itazU0Tl9N7GROwvDBhBY5S-_CcVGeNgFHd-Gaf5xpBHwR7kGhV-h0Lw$"><span style="color:#0563C1">ITHAKA</span></a> <b>/</b> 301 E. Liberty St, Suite 250, Ann Arbor, MI 48104<br>
Email: <a href="mailto:Spencer.Thomas@ithaka.org"><span style="color:#0563C1">Spencer.Thomas@ithaka.org</span></a><o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:black">Voicemail: +1-734-887-7004<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:black"> </span><o:p></o:p></p>
</div>
<p class="MsoNormal" style="margin-bottom:12.0pt"><o:p> </o:p></p>
</div>
</body>
</html>