Next in thread → Next in month →

Re: [saml-dev] Returning user roles in the Assertion

From
Cantor, Scott <>
Date
2014-03-13T17:11:07+00:00
ID
Thread
Re: [saml-dev] Returning user roles in the Assertion
On 3/13/14, 11:31 AM, "Vasu Y" <> wrote:
>
>I would like to know:
>1) What is the best practice for sending user roles from IDP to SP.
>2) What are some of the widely used approaches (if not best practice) for
>sending user roles from IDP to SP.

There aren't widely used standard attributes for it, even in very mature
sectors like higher ed. We tend to put them in the eduPersonEntitlement
attribute from the eduPerson schema, in the memberOf attribute that's used
for LDAP groups, or custom attributes.

There are substantial best practices around attribute use and naming, that
are routinely ignored by commercial interests. [1]

-- Scott

[1] https://wiki.shibboleth.net/confluence/display/SHIB2/AttributeNaming
Next in thread → Next in month →