RE: [security-services] LDAP Attribute Profile (saml-profiles-saml2.0)

From
Scott Cantor <>
Date
2006-01-16T20:17:14+00:00
ID
002301c61ad9$d5ad5610$
Thread
RE: [security-services] LDAP Attribute Profile (saml-profiles-saml2.0)
> Right, I'd be happiest if the NameFormat was urn:oasis:names:tc:SAML: 
> 2.0:profiles:attribute:X500 and that implied OID URNs.

This was a proposal briefly, but only while the basic concept of NameFormat
was in flux (it would have had to be renamed NameProfile, or something).

> The next best thing would be NameFormat urn:oasis:names:tc:SAML: 
> 2.0:attrname-format:uri, as we have, but clear rules about how values  
> corresponding to certain OIDs will be encoded.

From my perspective, this is what we have now, only without the clear rules.
My "rules" as an implementer are that if a deployer says that an OID URN is
to be processed with the LDAP profile, then that's that AFAIC.

-- Scott