How to retrieve SP required attributes at the IDP before authentication
David Chadwick
d.w.chadwick at kent.ac.uk
Wed Mar 21 18:20:04 GMT 2012
Hi Bart
you have now (re)uncovered the same problem that I notified to Scott
several years ago i.e. the ability for an SP to dynamically request a
set of attributes from an IDP. We did produce a draft SAML extension for
this, but Scott said there was no interest in standardising this in the
OASIS group at the time.
We have implemented various different ways of solving the problem, one
of which uses metadata (but this is not properly supported in all
implementations).
Our latest attempt was presented at the fall Internet 2 workshop here,
http://events.internet2.edu/2011/fall-mm/agenda.cfm?go=session&id=10001962&event=1148
This generally does not require any changes to the SAML protocol, since
it only uses the SAML Attribute Request message, which allows different
attributes to be dynamically requested.
If the time is now ripe to try again, then we can let you have a copy of
our proposed changes to SAML
regards
David
On 21/03/2012 16:19, Cantor, Scott wrote:
> On 3/21/12 11:47 AM, "Dierick Bart"<bart.dierick at hotmail.com> wrote:
>> After
>> a lot of research I realised that it must be possible to provide the
>> required
>> attributes at the authentication request.
>
> If you define an extension and convince everybody to support it.
> Otherwise, no.
>
>> They
>> suggest that the required attributes can be setted in the metadata OR in
>> the
>> authentication request.
>
> They are wrong, there is no extension in SAML that permits the latter.
>
>> I was already able to put these attributes in the the metadata. But isn't
>> it
>> better to get these attributes in the authentication request? And by
>> value
>> instead of by reference?
>
> Not particularly, unless you think the request would be constantly
> changing based on factors that an SP would know about.
>
> -- Scott
>
>
> --
> To unsubscribe from this list send an email to dev-unsubscribe at shibboleth.net
>
--
*****************************************************************
David W. Chadwick, BSc PhD
Professor of Information Systems Security
School of Computing, University of Kent, Canterbury, CT2 7NF
Skype Name: davidwchadwick
Tel: +44 1227 82 3221
Fax +44 1227 762 811
Mobile: +44 77 96 44 7184
Email: D.W.Chadwick at kent.ac.uk
Home Page: http://www.cs.kent.ac.uk/people/staff/dwc8/index.html
Research Web site: http://www.cs.kent.ac.uk/research/groups/iss/index.html
Entrust key validation string: MLJ9-DU5T-HV8J
PGP Key ID is 0xBC238DE5
*****************************************************************
More information about the dev
mailing list