Uploaded image for project: 'PicketLink'
  1. PicketLink
  2. PLINK-547

Allow setting Subject NameID to the value of a mapping-module attribute or other things

    XMLWordPrintable

Details

    • Feature Request
    • Resolution: Done
    • Minor
    • PLINK_2.7.0.CR1
    • PLINK_2.1.X
    • SAML
    • None

    Description

      We've had a vendor that triggers part of their application authz process based on the NameID in the assertion response Subject.

      They were expecting to get an email address back and we were providing them with a username.

      It looks like no matter what NameID format they specify in their AuthN, we always respond with Format="urn:oasis:names:tc:SAML:2.0:nameid-format:persistent" and populate it with the principal of the logged in user.

      I don't think we necessarily try to do anything smart with the AuthN NameID request hint but it would be really useful if we could choose an attribute, say from the LdapAttributeMappingProvider to go into the NameID field on a per SP basis.

      https://wiki.shibboleth.net/confluence/display/SHIB2/NameIDAttributes for example

      Attachments

        Issue Links

          Activity

            People

              psilva@redhat.com Pedro Igor Craveiro
              rhit_dminnich Dustin Minnich
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: