Discussion:
Attribute name with "dot"
Zico
2014-09-02 18:39:48 UTC
Permalink
Hello Shibboleth gurus,

I am little bit curious about one issue regarding attribute naming in
Shibboleth ( IDP, specially ).
Do we have any restriction of creating some attributes which might have
"dot" in the name?

Say, if I want to create a custom attribute named "sp.email" which will
just get the values of "email"; is it possible to create such
"sp(dot)email" attribute? Or, it is not supported / suggested by
Shibboleth?

Thanks in advance!
--
Best,
Zico
Cantor, Scott
2014-09-03 06:22:40 UTC
Permalink
Post by Zico
Hello Shibboleth gurus,
I am little bit curious about one issue regarding attribute naming in
Shibboleth ( IDP, specially ).
Do we have any restriction of creating some attributes which might have
"dot" in the name?
Not that I know of, but it would probably not be a good idea for the usual
reasons that's generally not a good idea. It will break something
somewhere or end up requiring escaping.

-- Scott
--
To unsubscribe from this list send an email to users-unsubscribe-***@public.gmane.org
Dave Perry
2014-09-11 09:14:00 UTC
Permalink
Old topic but... staff email addresses here now have a . in - it didn't seem to break the IdP or our SP on our moodle instance which uses shibboleth SSO for some users (we were going to switch everyone on LDAP to Shibb, but have hit a problem with SSO to/from another of our websites when shibboleth is used - so that switch is on hold).

Dave

_________________________________________________
Dave Perry
eLearning Technologist, Hull College Group

Room L34 - Queens Gardens Library
Wilberforce Drive, Queen's Gardens, Hull, HU1 3DG
Extension 2230 / Direct Dial 01482 381930

* Need a fast reply? Try elearning-NOSDTyrR4+***@public.gmane.org *


-----Original Message-----
From: users-bounces-***@public.gmane.org [mailto:users-bounces-***@public.gmane.org] On Behalf Of Cantor, Scott
Sent: 03 September 2014 07:23
To: Shib Users
Subject: Re: Attribute name with "dot"
Post by Zico
Hello Shibboleth gurus,
I am little bit curious about one issue regarding attribute naming in
Shibboleth ( IDP, specially ).
Do we have any restriction of creating some attributes which might have
"dot" in the name?
Not that I know of, but it would probably not be a good idea for the usual reasons that's generally not a good idea. It will break something somewhere or end up requiring escaping.

-- Scott

--
To unsubscribe from this list send an email to users-unsubscribe-***@public.gmane.org

**********************************************************************
This message is sent in confidence for the addressee
only. It may contain confidential or sensitive
information. The contents are not to be disclosed
to anyone other than the addressee. Unauthorised
recipients are requested to preserve this
confidentiality and to advise us of any errors in
transmission. Any views expressed in this message
are solely the views of the individual and do not
represent the views of the College. Nothing in this
message should be construed as creating a contract.

Hull College owns the email infrastructure, including the contents.

Hull College is committed to sustainability, please reflect before printing this email.
**********************************************************************

TEXT
--
To unsubscribe from this list send an email to users-unsubscribe-***@public.gmane.org
Cantor, Scott
2014-09-11 21:55:26 UTC
Permalink
Post by Dave Perry
Old topic but... staff email addresses here now have a . in - it didn't
seem to break the IdP or our SP on our moodle instance which uses
shibboleth SSO for some users (we were going to switch everyone on LDAP
to Shibb, but have hit a problem with SSO to/from another of our websites
when shibboleth is used - so that switch is on hold).
Dots in values are very different than dots in attribute names.

-- Scott
--
To unsubscribe from this list send an email to users-unsubscribe-***@public.gmane.org
Peter Schober
2014-09-12 14:53:43 UTC
Permalink
Post by Cantor, Scott
Post by Dave Perry
Old topic but... staff email addresses here now have a . in - it didn't
seem to break the IdP or our SP on our moodle instance which uses
shibboleth SSO for some users (we were going to switch everyone on LDAP
to Shibb, but have hit a problem with SSO to/from another of our websites
when shibboleth is used - so that switch is on hold).
Dots in values are very different than dots in attribute names.
And on the wire basically all attribute names have dots in them (URNs
with OIDs, URLs), unless you're using "basic" nameFormat (which you
shouldn't).
So the original question was probably only about naming of "id" values
inside the IDP's attribute resolver and filter, not about anything
you'd send elsewhere. So any breakage would be confined to the IDP
itself, too.
-peter
--
To unsubscribe from this list send an email to users-unsubscribe-***@public.gmane.org
Loading...