Skip to Content.
Sympa Menu

shibboleth-dev - Re: SAML name identifiers

Subject: Shibboleth Developers

List archive

Re: SAML name identifiers


Chronological Thread 
  • From: Ian Young <>
  • To:
  • Subject: Re: SAML name identifiers
  • Date: Tue, 07 Mar 2006 16:37:01 +0000

Scott Cantor wrote:

I suppose the trick is to be able to achieve things like:

You left out NameIDPolicy, which is the more significant part. Metadata
might be a factor, but mostly it's what the SP asks for.

I'm still at a loss to see how an SP can do something which says essentially "I'd like a persistent identifier if you and the user are OK with that, but I can live with a transient one if that's all I can get". I can do that if the persistent identifier is expressed as an attribute, but I don't see how I can do it if it's expressed as a NameID, even with NameIDPolicy.

I'm not unhappy with that -- passing the optional thing as an attribute is what we do now -- I'm just trying to understand your earlier statement about not seeing much use for attribute ePTI.

-- Ian



Archive powered by MHonArc 2.6.16.

Top of Page