RE: [saml-dev] multiple attributes

From
<>
Date
2008-06-03T12:02:14+00:00
ID
Thread
RE: [saml-dev] multiple attributes
I would also recommend the multiple value approach.

 

There may be implementations that process each attribute very
independently and the second occurrence may simply overwrite the first.  Using a
single multi-valued attribute makes it quite clear that the attribute has two
values associated with it at the same time.

 

Rob Philpott 

RSA, the Security Division of EMC

Senior
Technologist | e-Mail: 
| Office: (781) 515-7115 | Mobile: (617) 510-0893

 

From: nitin dangwal
[mailto:] 

Sent: Monday, June 02, 2008 5:33 PM

To: Scott Cantor

Cc: Tom Scavo; SAML Developers

Subject: Re: [saml-dev] multiple attributes

 

Well,

 

OASIS recommends two <attributeValue> elements for a
single attribute is possible.

 

<AttributeValue>

[Any
Number] 

Contains a value of the
attribute. If an attribute contains more than one discrete value, it
isRECOMMENDED that each value appear in its own 

<AttributeValue>
element. If more than
one <AttributeValue>
element is supplied
for an attribute, and any of the elements have a datatype assigned through xsi:type, then all of the <AttributeValue>
elements must have
the identical datatype assigned. 

 

Although there are no restrictions as such. 

 

Regards,

Nitin Dangwal

 

On 6/2/08, Scott Cantor <> wrote:

> I can't find anything in
any of the SAML specs that prohibits multiple

> occurrences of the same attribute in a SAML attribute
assertion.  For

> example, if an IdP wished to assert two e-mail addresses, it seems the

> IdP could formulate one attribute with two values or two attributes

> (with the same name) each with a single value.  Am I
interpreting this

> correctly?

Far as I know.

-- Scott

---------------------------------------------------------------------

To unsubscribe, e-mail: 

For additional commands, e-mail: