CAS Protocol Milestone

Marvin Addison marvin.addison at gmail.com
Fri Aug 15 15:38:09 EDT 2014


> I would still strongly suggest that if you're going to
> whitelist/register/whatever, you just adopt the same EntityDescriptor data
> model we have.

I intend to follow that advice.

> Because a) it works for any SSO protocol I've ever seen

That's probably a good sign it's sufficient. I have no interest in
inventing a data model if not needed.

> I just don't know what profile options, if any, might exist. Perhaps none.
> In SAML, you have everything from whether to include attributes to
> signing/encryption settings

I considered making attribute resolution optional, but punted for
simplicity. I may reconsider implementing as a profile configuration.

M


More information about the dev mailing list