Skip to Content.
Sympa Menu

shibboleth-dev - RE: Shibboleth Service Provider Security Advisory [14 December 2004]

Subject: Shibboleth Developers

List archive

RE: Shibboleth Service Provider Security Advisory [14 December 2004]


Chronological Thread 
  • From: "Scott Cantor" <>
  • To: "'Oleksandr Otenko'" <>, "'Tom Scavo'" <>
  • Cc: <>
  • Subject: RE: Shibboleth Service Provider Security Advisory [14 December 2004]
  • Date: Wed, 15 Dec 2004 11:33:00 -0500
  • Organization: The Ohio State University

> Regardless, what unscoped attributes permit a suffix like that? None I
> know of.

To head off the obvious, email address obviously does. But that's not an
attribute anybody should be writing policy-based filtering rules around or
using for authz, so nobody should be "interpreting" the suffix. It's an
atomic value.

That's the difference between scoped and unscoped. To Shib, unscoped means
an atomic value.

-- Scott




Archive powered by MHonArc 2.6.16.

Top of Page