Skip to Content.
Sympa Menu

shibboleth-dev - RE: comments: draft-mace-shibboleth-arch-protocols-02

Subject: Shibboleth Developers

List archive

RE: comments: draft-mace-shibboleth-arch-protocols-02


Chronological Thread 
  • From: "Scott Cantor" <>
  • To: "'Tom Scavo'" <>, <>
  • Cc: <>
  • Subject: RE: comments: draft-mace-shibboleth-arch-protocols-02
  • Date: Wed, 17 Nov 2004 13:09:41 -0500
  • Organization: The Ohio State University

> This is not what I was referring to in my previous message, however.
> Once the SP receives the authn assertion and the fully qualified
> username (or whatever persistent identifier is agreed upon) from the
> IdP, that attribute must correlate with a user known to the VLE. Thus
> the VLE must recognize users by the same persistent identifier. So
> let me stop and ask: how are accounts created in your particular VLE?
> What is the source of the "usernames" known to your VLE?

EPPN? TargetedID? We already know how to do this type of thing. Using
unqualified usernames in databases is an example of how to create problems.
If your system already does, then you have a legacy issue no matter what,
but creating new systems like this is just asking for trouble.

-- Scott




Archive powered by MHonArc 2.6.16.

Top of Page