shibboleth-dev - Re: First draft of eduPerson/SAML profiles
Subject: Shibboleth Developers
List archive
- From: Tom Scavo <>
- To: Keith Hazelton <>
- Cc: , mace-dir <>
- Subject: Re: First draft of eduPerson/SAML profiles
- Date: Tue, 19 Apr 2005 09:42:12 -0400
- Domainkey-signature: a=rsa-sha1; q=dns; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:reply-to:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; b=eh148ln0bE1T/tQrMoVUu1ERytWftIDkWASRySLpczfc1I5sHjLTo5lIeaR48VEwUAzn+kwh2jRUb+d4uM+5yx4xOt4TGipb3uoR9zNQpuiRdbYdZ/Ve3I+/rog7kAtU3EIYEeKm8MMF80/BgN9yZPwMhtWFoFIA+THyk5NWjdg=
On 4/19/05, Keith Hazelton
<>
wrote:
>
> 1) How attributes are handled in Shibboleth today (and "historically").
> That is the topic of section 2 of the document.
> 2) How we propose to handle attributes in SAML 2 environments, including
> Shibboleth 2.x That is covered in section 3.
Right, so aren't you mixing a Shibboleth profile in section 2 with a
SAML profile in section 3? Moreover, the Shibboleth profile is
largely deprecated so perhaps it should be separated out.
> Looking at section 3 first, what is being proposed is scoped to
> 1) Attributes originating in X.520 and in RFC-defined extensions such
> as inetOrgPerson
> 2) Attributes defined by the MACE directory working group (which I
> chair).
If you consider section 3 by itself, two issues stand out. First,
eduPersonTargetedID (as an attribute) is pre-empted by
nameid-format:persistent (as a name identifier) so the need for
special attribute syntax is not clear. Second, the eduCourseOffering
example cries out for a complex content model that pre-packages the
URI as a set of attributes applicable to the course in question.
So the end result is kind of curious...the eduCourseOffering attribute
uses a simple content model while the eduPersonTargetedID employs a
complex content model. The two syntaxes seem to go in totally
different directions.
The main question (in my mind) is the need for eduPersonTargetedID (as
an attribute) in SAML2. I'm not seeing that, I guess.
Tom
- First draft of eduPerson/SAML profiles, Scott Cantor, 04/18/2005
- Re: First draft of eduPerson/SAML profiles, Alistair Young, 04/19/2005
- Re: First draft of eduPerson/SAML profiles, Keith Hazelton, 04/19/2005
- Re: First draft of eduPerson/SAML profiles, Tom Scavo, 04/19/2005
- Re: First draft of eduPerson/SAML profiles, Tom Scavo, 04/19/2005
- RE: First draft of eduPerson/SAML profiles, Scott Cantor, 04/19/2005
- Re: First draft of eduPerson/SAML profiles, Tom Scavo, 04/19/2005
- RE: First draft of eduPerson/SAML profiles, Scott Cantor, 04/19/2005
- Re: First draft of eduPerson/SAML profiles, Walter Hoehn, 04/19/2005
- RE: First draft of eduPerson/SAML profiles, Scott Cantor, 04/19/2005
- Re: First draft of eduPerson/SAML profiles, Tom Scavo, 04/19/2005
- RE: First draft of eduPerson/SAML profiles, Scott Cantor, 04/19/2005
- RE: First draft of eduPerson/SAML profiles, Scott Cantor, 04/19/2005
- Re: First draft of eduPerson/SAML profiles, Tom Scavo, 04/19/2005
- RE: First draft of eduPerson/SAML profiles, Scott Cantor, 04/19/2005
- RE: First draft of eduPerson/SAML profiles, Alistair Young, 04/19/2005
- RE: First draft of eduPerson/SAML profiles, Scott Cantor, 04/19/2005
- Re: First draft of eduPerson/SAML profiles, Tom Scavo, 04/19/2005
- Re: First draft of eduPerson/SAML profiles, Keith Hazelton, 04/19/2005
- Re: First draft of eduPerson/SAML profiles, Alistair Young, 04/19/2005
Archive powered by MHonArc 2.6.16.