How to retrieve SP required attributes at the IDP before authentication

David Chadwick d.w.chadwick at kent.ac.uk
Wed Mar 21 19:22:30 GMT 2012


Scott

this is rather disingenuous of you, given that you were not an author of 
the draft document, and were not proposed to be. Coupled with the fact 
that prior to the draft that George Inman and myself wrote, an earlier 
one addressing the same topic and written by Sampo Kellomaki, was also 
turned down by the SAML group for standardisation, shows that there was 
some significant opposition to it.

So, whilst the ability to dynamically request attributes from an IDP 
along with the authentication request, has been an item of interest to 
several different researchers over the years, it has not been something 
that the OASIS group has wanted to support (to date). It is possible to 
dynamically request attributes using the Attribute Query after an Authn 
Query, but this requires two round trips. What we proposed was an 
enhanced Authn Request that allows it to be done in a single round trip.

Given the fact that you are not being asked to edit or shepherd the 
document, and the draft already exists, if it was re-submitted to the 
OASIS group, do you think there would still be strong opposition to it 
being standardised?

regards

David


On 21/03/2012 18:24, Cantor, Scott wrote:
> On 3/21/12 2:20 PM, "David Chadwick"<d.w.chadwick at kent.ac.uk>  wrote:
>
>> Hi Bart
>>
>> you have now (re)uncovered the same problem that I notified to Scott
>> several years ago i.e. the ability for an SP to dynamically request a
>> set of attributes from an IDP. We did produce a draft SAML extension for
>> this, but Scott said there was no interest in standardising this in the
>> OASIS group at the time.
>
> No. What I said was, I had no interest (and I still don't). I'm not going
> to edit, shepherd, and then implement something I don't think solves a
> compelling problem lots of people are asking me to solve. That doesn't
> stop anybody else from doing any OASIS work they like, or ignoring OASIS
> and just writing it.
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to dev-unsubscribe at shibboleth.net
>

-- 

*****************************************************************
David W. Chadwick, BSc PhD
Professor of Information Systems Security
School of Computing, University of Kent, Canterbury, CT2 7NF
Skype Name: davidwchadwick
Tel: +44 1227 82 3221
Fax +44 1227 762 811
Mobile: +44 77 96 44 7184
Email: D.W.Chadwick at kent.ac.uk
Home Page: http://www.cs.kent.ac.uk/people/staff/dwc8/index.html
Research Web site: http://www.cs.kent.ac.uk/research/groups/iss/index.html
Entrust key validation string: MLJ9-DU5T-HV8J
PGP Key ID is 0xBC238DE5

*****************************************************************


More information about the dev mailing list