Adding option to suppress NotBefore condition in assertions?

Michael A Grady mgrady at unicon.net
Fri Dec 28 14:26:54 EST 2012


On Dec 28, 2012, at 1:03 PM, Cantor, Scott wrote:

> I don't believe there are significant tests of the profile layer. Rod can
> correct me, but I don't see them.
> 
> The code related to profile configuration is actually inside
> shibboleth-common, while the profile handlers themselves are in the idp
> project.
> 
> One of the more confusing things is that there's configuration logic for
> the profile handlers inside the idp project, but the options that we're
> talking about here are in shibboleth-common. Looking at the existing flags
> is the best way to clearly see which is which.

Thanks. Yes, I had noticed that there were key pieces in both projects, and was indeed going to look at an existing flag or two as a guide.

By the way, when I'd first brought this up back in October, I'd asked what to call this flag and you suggested your preference would be:

  includeConditionsNotBefore

presumably with a default of "true", and a value of "false" to suppress the NotBefore condition being added. Is that still your preferred name for this option?

From back in October:
>> 
>> If we were to create such a configuration attribute, what should it be
>> called? Would "omitNotBeforeCondition" with a default value of "false",
>> but which could be set to "true", be ok? Or would it be easier to
>> understand/"harder to misinterpret" if we did that in a positive tone and
>> made it "includeNotBeforeCondition", with a default value of "true"? Or
>> something else entirely?
> 
> includeConditionsNotBefore would probably be my preference.


> 
> -- Scott
> 


--
Michael A. Grady
Senior IAM Consultant, Unicon, Inc.



More information about the dev mailing list