Skip to Content.
Sympa Menu

comanage-users - Re: [comanage-users] ePPN in COPerson

Subject: COmanage Users List

List archive

Re: [comanage-users] ePPN in COPerson


Chronological Thread 
  • From: Benn Oshrin <>
  • To: Paul Caskey <>
  • Cc: "" <>
  • Subject: Re: [comanage-users] ePPN in COPerson
  • Date: Fri, 14 Apr 2017 11:12:43 -0500
  • Ironport-phdr: 9a23:Kol2TxMyQx/ZA2/3QZsl6mtUPXoX/o7sNwtQ0KIMzox0I/7+rarrMEGX3/hxlliBBdydsKMazbCO+PGwEUU7or+5+EgYd5JNUxJXwe43pCcHRPC/NEvgMfTxZDY7FskRHHVs/nW8LFQHUJ2mPw6arXK99yMdFQviPgRpOOv1BpTSj8Oq3Oyu5pHfeQtFiT68bL9oMhm6sQrdu80VjIB/Nqs/1xzFr2dSde9L321oP1WTnxj95se04pFu9jlbtuwi+cBdT6j0Zrw0QrNEAjsoNWA1/9DrugLYTQST/HscU34ZnQRODgPY8Rz1RJbxsi/9tupgxCmXOND9QL4oVTi+6apgVQTlgzkbOTEn7G7Xi9RwjKNFrxKnuxx/2JPfbIWMOPZjYq/RYdYWSGxcVchTSiNBGJuxYZYRAeoPPehWrIfzqFUBohS8GQaiC/jiyiNRhnLswaE2z+osHAHA0Qc9H9wOqnPUrNDtOaoPT++1yq/IxijaYfNN2Tf98onIchY8qvyLRr1/b8zRyU8oFw7ej1WQr5DlMC2P1uQLrWeb8/RsWfixhGE6tgF8uz6izdoihInOg4Ia0FHE9SNhzYY0I924VFB0YcSiEJROqyGWKZF6Td0/TGF1visx174IuYajcSQU1JgqxATTZviFfoSS/x7uWvidLS1miH55e7+znxa//VS6xuHiSsW4zUxGoy5Fn9XWqHwA1wDf586aQfVn5EihwyyA1wXL5+FEP080ka3bJoYhwr43k5oTsFrMHirsl0X3iK+ab18r9+ay5+ToeLnpu4WcOJFuhQH7MqQunde/AfgiPgcSWGib/Pyw1Lzl/ULnXLVHluM6nrXavZzAIckWpLS1DxJb34o98RqzESuq3dcAkXkCNl1FeRaHj4bzO1HJJfD1FeywjEqqkDdtwPDLJbzhApPRLnfdirfhe6hy61JCxAYp099Q+o9UBqkbIP3vQk/xqMDYDhghPgOoxObnDc9y1oUEVmKAHKCVKb7SsUSW6eI1OOmBf4sVuDfmK/g5/P7ik2U1mV4bfam1w5QXcna4Eep6I0mHe3bjnMoOEXoStAokUOPqkEGCUSJUZ3uqR6Iz+is0CJmlDYjdRoGgm72B3CGnHpJIfGBGDE6DEWv2e4meRfgDdT+ScYddlWk8XKWlA6QozhKjpUeu07FuNenZ6wUZs47uzt54+7eVmB0vo29aFcOYhkuASWc8uXgIXT4wlPR1rEp7zX+C17R1mfpVCYYV6v9UBFRpfaXAxvB3XoihEjnKec2EHRP/Go2r

We probably need better documentation on this (possible admin manual
document?) but typically this is the procedure most deployments use:

(1) Configure shib SP to populate $REMOTE_USER with desired attribute.
(2) Configure enrollment flow to require email verification/confirmation
and require authentication (set mode to probably Review or maybe
Automatic depending on your preference).
(3) Do NOT define an Enrollment attribute for ePPN. It will be
automatically populated into the Org Identity during enrollment.
(4) This places the ePPN into the Org Identity, not the CO Person record
(which is appropriate since it's not a CO/VO attribute), so to populate
it into LDAP you need to tick the 'Copy value from Org Identity'
configuration for the attribute you want to populate into. This probably
isn't eduPersonPrincipleName, since that's single valued, and in a VO
context this is a multivalued attribute. See discussions in MACE-dir,
but for now the workaround is to pick a different attribute (like uid).

See also


https://spaces.internet2.edu/display/COmanage/Registry+Enrollment+Flow+Configuration#RegistryEnrollmentFlowConfiguration-EmailVerification(Confirmation)andAuthentication

There are other, more complicated ways to do this as well, but this is
usually the starting point.

Thanks,

-Benn-

On 4/14/17 9:51 AM, Paul Caskey wrote:
> Howdy!
>
>
>
> I’m trying to get ePPN from an authenticated enrollment flow into the
> COPerson.
>
>
>
> It’s making it into the Org Person (along with validated email addr),
> but not the COPerson.
>
>
>
> I see that I can probably define ePPN as an enrollment attribute, then
> force it to be copied to the CO Person object, but I don’t want to
> display a box on the enrollment form asking the user for their ePPN.
>
>
>
> So, what am I missing on populating ePPN in CO Person objects? J
>
>
>
>
>
>
>
> Thanks!
>
>
>



Archive powered by MHonArc 2.6.19.

Top of Page