13.07.2015 Views

Liberty ID-FF Bindings and Profiles Specification - Liberty Alliance

Liberty ID-FF Bindings and Profiles Specification - Liberty Alliance

Liberty ID-FF Bindings and Profiles Specification - Liberty Alliance

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>Liberty</strong> <strong>Alliance</strong> Project:<strong>Liberty</strong> <strong>ID</strong>-<strong>FF</strong> <strong>Bindings</strong> <strong>and</strong> <strong>Profiles</strong> <strong>Specification</strong>Version: 1.2-errata-v2.020192020202120222023202420253.7. NameIdentifier Mapping ProfileThe NameIdentifier mapping profile specifies how a service provider may obtain a NameIdentifier for a Principal ithas federated in the "namespace" of a different service provider, by querying an identity provider that has federatedthe Principal with both service providers. This NameIdentifier may be used to obtain additional information about aPrincipal from a SAML authority, or used for other non-specific purposes. In most cases, the encryption profile in thefollowing section will be used to obfuscate <strong>and</strong> time-limit this identifier to restrict its use.The NameIdentifier mapping profile makes use of the following metadata elements, as defined in [<strong>Liberty</strong>Metadata]:202620272028• NameIdentifierMappingProtocolProfile - A URI indicating the profile of this protocol supported by theidentity provider.• SOAPEndpoint - The SOAP endpoint location at the identity provider to which <strong>Liberty</strong> SOAP messages are sent.202920302031203220332034203520363.7.1. SOAP-based NameIdentifier MappingThe SOAP-based profile relies on a SOAP request <strong>and</strong> response to query for <strong>and</strong> return the NameIdentifier. Arequesting service provider issues a SOAP request to an identity provider, requesting a different NameIdentifier for anamed Principal in the namespace of a service provider or affiliation group. This NameIdentifier may then be usedto query another <strong>Liberty</strong> provider offering SAML services for additional information about the named Principal. SeeFigure 17.The following URI-based identifier MUST be used when referencing this specific profile:URI: http://projectliberty.org/profiles/nim-sp-httpService Provider 1Service Provider 2(Attribute Provider)Identity Provider1. SOAP POST:()2. SOAP 200 OK: ()3. SOAP POST: ()4. SOAP 200 OK: ()20372038Figure 17. SOAP-based profile for name identifier mapping20392040204120422043204420453.7.1.1. Step 1: Issuance <strong>and</strong> processing of RequestIn step 1, the service provider sends a SOAP over HTTP request to the SOAP endpoint of the identity provider it isquerying. The SOAP message MUST contain exactly one element inthe SOAP body <strong>and</strong> adhere to the construction rules defined in [<strong>Liberty</strong>ProtSchema].The identity provider MUST process the according to the rules definedin [<strong>Liberty</strong>ProtSchema]. The identity provider is NOT required to honor the request for a mapped NameIdentifier, butit MUST respond to the request with an appropriate status.<strong>Liberty</strong> <strong>Alliance</strong> Project59

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!