Skip to Content.
Sympa Menu

grouper-users - Re: [grouper-users] SAML1 name of isMemberOf

Subject: Grouper Users - Open Discussion List

List archive

Re: [grouper-users] SAML1 name of isMemberOf


Chronological Thread 
  • From: Keith Hazelton <>
  • To:
  • Subject: Re: [grouper-users] SAML1 name of isMemberOf
  • Date: Mon, 21 Nov 2011 20:07:43 -0600

Takeshi,

urn's using attribute-def naming are a legacy of SAML 1.1 days.

For SAML 2, the URN oid namespace is used, so the attribute with the friendly name "isMemberOf" is represented by "urn:oid:1.3.6.1.4.1.5923.1.5.1.1" per its definition in "LDAP representations of membership in groups" (http://middleware.internet2.edu/dir/docs/internet2-mace-dir-ldap-group-membership-200507.html )

The applicable SAML 2 document is "Profiles for the OASIS Security Assertion Markup Language (SAML) V2.0"









Hi all,

Just a quick question.

https://spaces.internet2.edu/display/Grouper/Exposing+Groups+Through+Shibboleth
          name="urn:mace:dir:attribute-def:isMemberOf" />

Is this a registered URN for isMemberOf?
Or where can I confirm it?

I couldn't find in:
http://middleware.internet2.edu/urn-mace/urn-mace-dir-attribute-def.html

Best regards,
Takeshi




Archive powered by MHonArc 2.6.16.

Top of Page