Skip to Content.
Sympa Menu

comanage-users - Re: [comanage-users] How to collect eppn with self-signup?

Subject: COmanage Users List

List archive

Re: [comanage-users] How to collect eppn with self-signup?


Chronological Thread 
  • From: Mike Manske <>
  • To:
  • Subject: Re: [comanage-users] How to collect eppn with self-signup?
  • Date: Tue, 20 Jun 2017 09:32:31 -0500
  • Ironport-phdr: 9a23:aGQupBx+La8mGmzXCy+O+j09IxM/srCxBDY+r6Qd2+sWIJqq85mqBkHD//Il1AaPBtSEraIUwLSP+4nbGkU4qa6bt34DdJEeHzQksu4x2zIaPcieFEfgJ+TrZSFpVO5LVVti4m3peRMNQJW2aFLduGC94iAPERvjKwV1Ov71GonPhMiryuy+4ZPebgFKiTanYr5/Lxq6oATMusILnYZsN6E9xwfTrHBVYepW32RoJVySnxb4+Mi9+YNo/jpTtfw86cNOSL32cKskQ7NWCjQmKH0169bwtRbfVwuP52ATXXsQnxFVHgXK9hD6XpP2sivnqupw3TSRMMPqQbwoXzmp8qFmQwLqhigaLT406GPYisJwgqxVoxyvugJxzJLbboyOKPp+Z7nQcc8GSWZdXMtcUTFKDIOmb4sICuoMJeFWr4j+p1QQsBCwAhOjBOX0yj9LmHD9wKo30+EkEQ7c2gwgBNEOv2rKoNjuO6cSVPq6zKjMzTnZc/xW3jL95ZHOfxs8r/+MWrdwftDQyUkpDw7Fj1OQqZD7MDOP0OQCrXSb4/R6We2xlmEntgd8qSWsyMc0koTFmIMYxkzG+Ch8zoY4Jsa3RFJ+bNOrDJdcqzyWOo5qTc8+QmxlvSM3xqMYtZGgeiUB1Y4pyATFa/OddoiF+hLjW/iVITd/nH9lfaiwhxe28US5y+38UdW43E9FryZbjNXDrWoB1xPU6siARft9+lmu1SyT2ADU7+FIOUE0lazFJJ492rM8iJsevVjBEyLzlkX7j7SZelkh9+Wn9+jrfqjqq5qAOINoiwzzN6EjltKhDesjKgQOWnKU+eW41L3t5035R7BKg+Uzkqncqp/aI98bpq2nDANLyYsj5BO/AC2n0NQch3UIMFVFeBefg4jzJ17OOOz4Deu4g1m0jDhrwPXGMafnAprXIXjMjq7tfatm60FC0goz1stS55ZVCrEaPPLzQVH9uMbZDh8/Lwy73fznCNNj2YMCR26DGLGWP77PsQzA2uV6KO6JbYkctzu4NuMo/eXGjHkllEUbcLXzm5YbdSOWBPNjdmCYYnekp94HCmQH9l47SeXsk16PCxZcYn+zW+Q34TRtW9HuNpvKWo342O/J5yy8BJADPm0=

We use self-signup, and require login so we can capture the eppn. We
direct a user to a landing page with instructions that requires login.
That page directs them, via link, to the self-signup enrolment form.

MikeM


On Tue, Jun 20, 2017 at 8:53 AM, Benn Oshrin
<>
wrote:
> Right, IIRC there's no way to mark an identifier pulled from $ENV as a
> login identifier atm. That code is scheduled to be refactored in the not
> too distant future...
>
> On 6/20/17 9:49 AM, Mihály Héder wrote:
>> Hi,
>>
>> ah, no. I assume that the email-by-invite enrollment method is also an
>> implicit email verification and that is why it works there and not my
>> self-signup flow?
>> I will enable the email verification then. Although in most of the cases
>> I have a pretty solid, idp-asserted email address from the federated
>> authentication in the apache environment, so it is a bit unfortunate
>> that the collection of the eppn is tied to email verification.
>>
>> Mihály
>>
>> On Tue, Jun 20, 2017 at 1:21 PM, Benn Oshrin
>> <
>> <mailto:>>
>> wrote:
>>
>> Hi Mihály,
>>
>> Are you using email confirmation with self signup?
>>
>>
>> https://spaces.internet2.edu/display/COmanage/Registry+Enrollment+Flow+Configuration#RegistryEnrollmentFlowConfiguration-EmailVerification(Confirmation)andAuthentication
>>
>> <https://spaces.internet2.edu/display/COmanage/Registry+Enrollment+Flow+Configuration#RegistryEnrollmentFlowConfiguration-EmailVerification(Confirmation)andAuthentication>
>>
>> Thanks,
>>
>> -Benn-
>>
>> On 6/20/17 6:34 AM, Mihály Héder wrote:
>> > Hi List,
>> >
>> > I encountered a problem about self-signup enrollment flows. In case
>> of
>> > invitations, I can configure the enrollment flow so that it will
>> require
>> > login and the organizational entity that gets created will have the
>> > proper eppn session associated to it, taken from the shibboleth
>> session..
>> >
>> > However, I could not achieve the same functionality in case of
>> > self-signup. I can get all kinds of attributes name, title, email,
>> etc)
>> > from the session or I can even get the eppn in some other field
>> into if
>> > I set up the environment variable name so. But I cannot get it as
>> eppn
>> > unfortunately.
>> >
>> > Why is this? Is it possible that there is no such feature with
>> > self-signup or is it just a configuration issue?
>> >
>> > Thank you
>> >
>> > Mihály
>> >
>>
>>
>>
>>
>> --
>> Mihály Héder, PhD
>> Research Fellow
>> Institute for Computer Science and Control
>> Hungarian Academy of Sciences



Archive powered by MHonArc 2.6.19.

Top of Page