grouper-users - Re: [grouper-users] SAML1 name of isMemberOf
Subject: Grouper Users - Open Discussion List
List archive
- From: Keith Hazelton <>
- To:
- Subject: Re: [grouper-users] SAML1 name of isMemberOf
- Date: Mon, 21 Nov 2011 20:07:43 -0600
Takeshi, For SAML 2, the URN oid namespace is used, so the attribute with the friendly name "isMemberOf" is represented by "urn:oid:1.3.6.1.4.1.5923.1.5.1.1" per its definition in "LDAP representations of membership in groups" (http://middleware.internet2.edu/dir/docs/internet2-mace-dir-ldap-group-membership-200507.html ) The applicable SAML 2 document is "Profiles for the OASIS Security Assertion Markup Language (SAML) V2.0" Refer to section 8.2.2 (beginning on page 51): "8.2.2 SAML Attribute Naming The NameFormat XML attribute in <Attribute> elements MUST be urn:oasis:names:tc:SAML:2.0:attrname-format:uri. To construct attribute names, the URN oid namespace described in IETF RFC 3061 [RFC3061] is used. In this approach the Name XML attribute is based on the OBJECT IDENTIFIER assigned to the directory attribute type. Example: urn:oid:2.5.4.3 Since X.500 procedures require that every attribute type be identified with a unique OBJECT IDENTIFIER, this naming scheme ensures that the derived SAML attribute names are unambiguous." Hope that helps, --Keith Hazelton ___________ On Nov 21, 2011, at 7:24 PM, Takeshi NISHIMURA wrote:
|
- [grouper-users] SAML1 name of isMemberOf, Takeshi NISHIMURA, 11/21/2011
- Re: [grouper-users] SAML1 name of isMemberOf, Keith Hazelton, 11/21/2011
- Re: [grouper-users] SAML1 name of isMemberOf, Takeshi NISHIMURA, 11/21/2011
- Message not available
- Message not available
- Message not available
- Re: [grouper-users] SAML1 name of isMemberOf, Keith Hazelton, 11/21/2011
- Re: [grouper-users] SAML1 name of isMemberOf, Takeshi NISHIMURA, 11/21/2011
- Re: [grouper-users] SAML1 name of isMemberOf, Keith Hazelton, 11/21/2011
- Message not available
- Message not available
- Re: [grouper-users] SAML1 name of isMemberOf, Tom Barton, 11/22/2011
- Re: [grouper-users] SAML1 name of isMemberOf, Takeshi NISHIMURA, 11/22/2011
- Message not available
- Re: [grouper-users] SAML1 name of isMemberOf, Takeshi NISHIMURA, 11/21/2011
- Re: [grouper-users] SAML1 name of isMemberOf, Keith Hazelton, 11/21/2011
Archive powered by MHonArc 2.6.16.