...
The following attributes contribute to a minimal gateway attribute bundle:
eduPersonTargetedID
(ePTID
)eduPersonPrincipalName
(ePPN
)mail
displayName
OR (givenName
ANDsn
)
Recommendations:
- Set
ePPN
to the user’s email address- Use
ePPN
at your own risk
- Use
- Set the ‘mail’
mail
attribute to the user’s email address - Set the person name as appropriate
- Optionally set the
NameID
to one of the following:- the user’s email address
ePTID
(i.e., a SAML2 PersistentNameID
)- SAML2 Transient
NameID
(default)
The most difficult mapping is ePTID. The goal is to assert a value of ePTID that persists with or without the gateway in the middle.
...