Opinions on SIDP-570?

Christopher Bongaarts cab at umn.edu
Mon Feb 18 12:40:40 EST 2013


On 2/18/2013 11:20 AM, Cantor, Scott wrote:
> Issue filed here:
> https://issues.shibboleth.net/jira/browse/SIDP-570
>
> Basically it's asking us to look into exposing the entityID as the
> "service name" for anonymous SPs for IdPs that are configured to allow
> anonymous SPs.
>
> My off-the-cuff reaction is, I don't like the idea of displaying anything
> that might be interpreted as "reasonable belief of the IdP" about a
> request when we have no such evidence.
>
> OTOH, since we don't generally require signed requests from the SPs we do
> know, that doesn't exactly scream consistency.

We don't use anonymous relying parties here, but IMHO it should behave 
similarly to whatever it returns for a "registered" SP that has no UI 
info tags in its metadata.  Then maybe add a tag (if there's not one 
already) to easily allow for conditional display (e.g. a "has metadata" 
seal of approval) based on whether the current RP is anonymous or not.

-- 
%%  Christopher A. Bongaarts   %%  cab at umn.edu          %%
%%  OIT - Identity Management  %%  http://umn.edu/~cab  %%
%%  University of Minnesota    %%  +1 (612) 625-1809    %%


More information about the dev mailing list