Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Should basic IAM data (netids, UPI, email address) be synchronized between these environments more frequently? 

You say "Potato" and I say B6BCC1F2-C25B-4273-8927-B769E73D8BE4

Different Cloud partners have different names for the same thing. Different partners have different meanings for the same word. There are different standards available.

What we normally call the Last Name (in the US) poses a problem because in China the family name comes first and then the given name. Some systems know this, while other systems are not so sophisticated. In different standards, this data field can be called the "sn", "surname", http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname, http://schemas.xmlsoap.org/claims/LastName, or "urn:oid:2.5.4.4".

Different partners have different limitations on the values allowed for certain identity fields. The number of allowable values for "sex" has become more complicated recently.

Mapping between an internal semantic system (a database) and an external semantic system (an XML schema) is an ongoing problem. Boundary IAM systems (like Shibboleth or ADFS) may have to adapt internal values to more restricted value systems required by a Cloud partner.