Ken Weiss
2014-08-29 21:59:32 UTC
Hi,
I'm not sure if this is a question for this list or not. If I'm in the
wrong place, please direct me to the right place...
We have several applications sitting behind Shibboleth SPs that rely on
the EPPN to uniquely identify a user. One of the IDPs with which we
integrate just told me that they use the authenticated user's email
address as the EPPN. Because email addresses change frequently, so do the
EPPNs in this IDP. The IDP manager did mention, though, that they also use
the eduPersonTargetedID attribute, and that one is guaranteed to be both
unique and stable.
Is the eduPersonTargetedID at least as widely used as the EPPN? Is the
eduPersonTargetedID always guaranteed to be unique and stable? I know
eduPersonTargetedID is not part of the standard Research and Scholarship
category attribute set, so I'm somewhat hesitant to change our application
to rely on that, instead of EPPN.
Maybe what I really want to ask is this: What attribute do you recommend
using as a unique identifier for a Shibboleth-authenticated user?
--Ken
------------------------------------------------------------
Ken Weiss ken.weiss-E+***@public.gmane.org
UC Office of the President 510-587-6311 (office)
California Digital Library 916-905-6933 (mobile)
UC Curation Center
415 20th Street, 4th Floor
Oakland, CA 94612
I'm not sure if this is a question for this list or not. If I'm in the
wrong place, please direct me to the right place...
We have several applications sitting behind Shibboleth SPs that rely on
the EPPN to uniquely identify a user. One of the IDPs with which we
integrate just told me that they use the authenticated user's email
address as the EPPN. Because email addresses change frequently, so do the
EPPNs in this IDP. The IDP manager did mention, though, that they also use
the eduPersonTargetedID attribute, and that one is guaranteed to be both
unique and stable.
Is the eduPersonTargetedID at least as widely used as the EPPN? Is the
eduPersonTargetedID always guaranteed to be unique and stable? I know
eduPersonTargetedID is not part of the standard Research and Scholarship
category attribute set, so I'm somewhat hesitant to change our application
to rely on that, instead of EPPN.
Maybe what I really want to ask is this: What attribute do you recommend
using as a unique identifier for a Shibboleth-authenticated user?
--Ken
------------------------------------------------------------
Ken Weiss ken.weiss-E+***@public.gmane.org
UC Office of the President 510-587-6311 (office)
California Digital Library 916-905-6933 (mobile)
UC Curation Center
415 20th Street, 4th Floor
Oakland, CA 94612
--
To unsubscribe from this list send an email to users-unsubscribe-***@public.gmane.org
To unsubscribe from this list send an email to users-unsubscribe-***@public.gmane.org