Skip to Content.
Sympa Menu

shibboleth-dev - Re: [Shib-Dev] Obtaining user attributes from a web form at the time of authentication

Subject: Shibboleth Developers

List archive

Re: [Shib-Dev] Obtaining user attributes from a web form at the time of authentication


Chronological Thread 
  • From: "Dharam Veer" <>
  • To:
  • Subject: Re: [Shib-Dev] Obtaining user attributes from a web form at the time of authentication
  • Date: Mon, 27 Oct 2008 11:49:08 -0500
  • Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=message-id:date:from:to:subject:in-reply-to:mime-version :content-type:references; b=oL4Fs815lDs12CHXoHfsGfjVTsg5u1TdOFihurlv3vWTZsMyd9vJJx6JpOUwRjZvYn EbL79DKlF9NYhiNfL/Q1YC8oJnJQUlfzMHcrSm9nnLgXWuOz/bUrQAGz0d/qLNd108oU /JSJ/SdpP6+UOfRWV3g/SMJy8vhXiS5PnbHrI=

Dear Tom,

Thanks for this clarification. I am looking at OAuth as per your suggestion and it does look interesting. I hope that it has some way to establish trust using x509 like SAML.

>> The OASIS SSTC
>> has discussed the possibility of including attributes in AuthnRequest,
>> and in fact, this is an action item waiting for someone to write the
>> profile.

Is there any public link which talks about it ?.

Best regards

On Mon, Oct 27, 2008 at 11:42 AM, Tom Scavo <> wrote:
On Mon, Oct 27, 2008 at 12:27 PM, Dharam Veer <> wrote:
>
> 1/ As part of AuthnRequest you can't specify the attributes required.
> Attribute Query/Response is the thing to use for this. [Please correct me if
> I misunderstood the spec]

You have correctly understood the current spec, yes.  The OASIS SSTC
has discussed the possibility of including attributes in AuthnRequest,
and in fact, this is an action item waiting for someone to write the
profile.  No idea when this might become concrete.

Tom




Archive powered by MHonArc 2.6.16.

Top of Page