I would also recommend the multiple value approach.
There may be implementations that process each attribute very
independently and the second occurrence may simply overwrite the first. Using a
single multi-valued attribute makes it quite clear that the attribute has two
values associated with it at the same time.
Rob Philpott
RSA, the Security Division of EMC
Senior
Technologist | e-Mail:
| Office: (781) 515-7115 | Mobile: (617) 510-0893
From: nitin dangwal
[mailto:]
Sent: Monday, June 02, 2008 5:33 PM
To: Scott Cantor
Cc: Tom Scavo; SAML Developers
Subject: Re: [saml-dev] multiple attributes
Well,
OASIS recommends two <attributeValue> elements for a
single attribute is possible.
<AttributeValue>
[Any
Number]
Contains a value of the
attribute. If an attribute contains more than one discrete value, it
isRECOMMENDED that each value appear in its own
<AttributeValue>
element. If more than
one <AttributeValue>
element is supplied
for an attribute, and any of the elements have a datatype assigned through xsi:type, then all of the <AttributeValue>
elements must have
the identical datatype assigned.
Although there are no restrictions as such.
Regards,
Nitin Dangwal
On 6/2/08, Scott Cantor <> wrote:
> I can't find anything in
any of the SAML specs that prohibits multiple
> occurrences of the same attribute in a SAML attribute
assertion. For
> example, if an IdP wished to assert two e-mail addresses, it seems the
> IdP could formulate one attribute with two values or two attributes
> (with the same name) each with a single value. Am I
interpreting this
> correctly?
Far as I know.
-- Scott
---------------------------------------------------------------------
To unsubscribe, e-mail:
For additional commands, e-mail: