wiki error
Cantor, Scott
cantor.2 at osu.edu
Fri Jul 5 12:11:02 EDT 2013
On 7/4/13 1:15 AM, "David Champion" <dgc at uchicago.edu> wrote:
>It's because under the default eppn attribute policy, you need an
>expected scope, and you can only have that by having metadata for your
>issuer's entityID, which presumably the backdoor approach doesn't
>typically involve. (I certainly don't know what metadata for a fake
>issuer would look like....)
The same as metadata for any other, pretty much. There are certain
required elements that have to be faked at times, but the relevant
metadata is the same as any other case. It's just there has to be an
issuer specified to key into the metadata to use.
>Probably it would be useful to have this in a table of common errors.
>I don't know whether it would be preferable to create a new one for
>NativeSPBackDoor, or to cite it in the general SP errors triage page.
Since virtually nobody is using this feature, I probably wouldn't consider
it a common error at this point worth trying to address generically.
-- Scott
More information about the dev
mailing list