<div dir="ltr">To be more explicit, the constraint is HR's population of 'supervisor' into the directory that is the issue: they already populate conforming ePA values and can add the 'supervisor' value as part of the routine sync to the record of users who are supervisors, but they do NOT want to revise or add a new process to populate the value to a different attribute in AD. Or rather they will put it on their plan for future work, delaying the deployment of a new contracted service.</div><br><div class="gmail_quote gmail_quote_container"><div dir="ltr" class="gmail_attr">On Mon, Aug 25, 2025 at 3:54 PM Paul B. Henson <<a href="mailto:henson@cpp.edu">henson@cpp.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">> From: David Bantz<br>
> Subject: [EXT] non-conforming values of eduPersonAffiliation<br>
><br>
> What are the practical consequences of accepting such a non-conforming value?<br>
> Of course I realize there are multiple alternative tactics that would not violate<br>
> the ePA spec<br>
<br>
We have a local schema cppEduPerson with a corresponding cppEduPersonAffiliation we use to deal with local affiliations that aren't part of the standard. If they're willing to accept a different attribute with the same values plus the extra magic stuff that's a fairly simple alternative tactic.<br>
<br>
> positioning IAM as a roadblock to deploying this service. Other than my shame,<br>
> what would this entail? Are services that consume ePA likely to choke on an<br>
> unexpected out-of-spec value? Will our IdP be cast out of InCommon?<br>
<br>
Otherwise, you could always make it a scripted attribute or have multiple definitions with activation conditions such that the nonstandard values for the attribute only show up where they are supposed to and not other random consumers of the attribute.<br>
<br>
OTOH, I've always refused to use nonstandard values for standardized attributes. I've never said we would get booted out of InCommon for violating their standards, but I've also never said there wouldn't potentially be repercussions ;)...<br>
<br>
</blockquote></div>