Opinions on SIDP-570?
Christopher Bongaarts
cab at umn.edu
Mon Feb 18 12:40:40 EST 2013
On 2/18/2013 11:20 AM, Cantor, Scott wrote:
> Issue filed here:
> https://issues.shibboleth.net/jira/browse/SIDP-570
>
> Basically it's asking us to look into exposing the entityID as the
> "service name" for anonymous SPs for IdPs that are configured to allow
> anonymous SPs.
>
> My off-the-cuff reaction is, I don't like the idea of displaying anything
> that might be interpreted as "reasonable belief of the IdP" about a
> request when we have no such evidence.
>
> OTOH, since we don't generally require signed requests from the SPs we do
> know, that doesn't exactly scream consistency.
We don't use anonymous relying parties here, but IMHO it should behave
similarly to whatever it returns for a "registered" SP that has no UI
info tags in its metadata. Then maybe add a tag (if there's not one
already) to easily allow for conditional display (e.g. a "has metadata"
seal of approval) based on whether the current RP is anonymous or not.
--
%% Christopher A. Bongaarts %% cab at umn.edu %%
%% OIT - Identity Management %% http://umn.edu/~cab %%
%% University of Minnesota %% +1 (612) 625-1809 %%
More information about the dev
mailing list