wiki error
David Champion
dgc at uchicago.edu
Mon Jul 8 12:40:48 EDT 2013
* On 05 Jul 2013, Cantor, Scott wrote:
> On 7/4/13 1:15 AM, "David Champion" <dgc at uchicago.edu> wrote:
>
> >It's because under the default eppn attribute policy, you need an
> >expected scope, and you can only have that by having metadata for your
> >issuer's entityID, which presumably the backdoor approach doesn't
> >typically involve. (I certainly don't know what metadata for a fake
> >issuer would look like....)
>
> The same as metadata for any other, pretty much. There are certain
> required elements that have to be faked at times, but the relevant
> metadata is the same as any other case. It's just there has to be an
> issuer specified to key into the metadata to use.
I'm sure the document structure of the md is the same, but what elements
are used and useful? This is unclear to a person developing a backdoor.
For example, I'm unaware of anything that the SP needs to know about
my use case aside from this specific scoping attribute. I can mix and
bake the metadata, I just don't know what the functional ingredients are
for my scenario, which is fundamentally just using the SP as a session
manager independent of any other SAML context.
> >Probably it would be useful to have this in a table of common errors.
> >I don't know whether it would be preferable to create a new one for
> >NativeSPBackDoor, or to cite it in the general SP errors triage page.
>
> Since virtually nobody is using this feature, I probably wouldn't consider
> it a common error at this point worth trying to address generically.
Fair enough, but since pretty much anyone walking down this path will
encounter it unless they have advance information that I don't, it
should be described somewhere so that it doesn't frighten people who
aren't as prepared as I am to debug it themselves or contact the shib
list. So maybe the NativeSPBackdoor page itself is fine.
I'm happy to take a role in updating the backdoor doc, if that's OK with
you and everyone else involved. I'll even do guided howto with my end
result published -- this is or will be a completely open project. I
just want to be sure I'm putting the right things in the right places.
--
David Champion • dgc at uchicago.edu • University of Chicago
Enrico Fermi Institute • Computation Institute • USATLAS Midwest Tier 2
More information about the dev
mailing list