New Federated Error Handling Service (ACTION REQUIRED)

Olga Biasotti obiasotti at highwire.stanford.edu
Mon Jan 30 18:40:36 GMT 2012


Hi Tom,

Thank you for this information. I would like to investigate integrating this service for HighWire. Meantime, qhat is the best way to detect if an Error occurred in first place on the IdP site. Is there a standard way in HttpRequest to detect error on IdP side, or is this all up to the implementor?

Any info or pointers in this direction would be greatly appreciated. Thank you!

Sincerely,

Olga Biasotti

650-736-1548
HighWire Press
Stanford University
1454 Page Mill Road
Palo Alto CA 94304





On Jan 23, 2012, at 10:57 AM, Tom Scavo wrote:

> InCommon has launched a new centralized Federated Error Handling Service (https://spaces.internet2.edu/x/kJOVAQ) for use by all Service Providers (SPs) in the federation. The goal is to provide a better experience for users in the event that they are unable to access a federated service, which will help prevent them from becoming confused or frustrated.
> 
> In many situations, the identity provider (IdP) does not provide the SP with sufficient information (attributes) to make an access control decision. Just telling a user that "the necessary attributes are not being released" usually does not help. We need to give users information and tools that will help them solve their problems.
> 
> Using this new service, SPs can automatically generate simple but effective error pages for the end user. These dynamic error pages rely on the Error Handling URL in IdP metadata, which provides a pointer to a comprehensive IdP support page for users that experience difficulties during federated login.
> 
> In order for this service to work effectively, IdP operators need to add the Error Handling URL in their metadata. Please do so today.
> 
> SP operators use the Federated Error Handling Service to automatically build and display a custom error page. The service takes advantage of MDUI elements in metadata (https://spaces.internet2.edu/x/2YGKAQ) to customize an SP-branded page displaying the SP's logo and text specific to the SP and IdP in question. Visit the wiki for examples and instructions how to incorporate the Error Handling Service into your SP deployment (https://spaces.internet2.edu/x/kJOVAQ).
> 
> We continue to look for ways to improve and expand on the tools available for use by site administrators. Please let us know if you have suggestions or questions (admin at incommon dot org).
> 
> Tom Scavo
> Operations Manager
> InCommon.org

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/dev/attachments/20120130/6a9f9a3b/attachment.html 


More information about the dev mailing list