Default RP config for SAML 1 and attribute-release ?

Tom Zeller tzeller at dragonacea.biz
Sun Dec 21 17:42:09 EST 2014



> On Dec 21, 2014, at 3:09 PM, "Cantor, Scott" <cantor.2 at osu.edu> wrote:
> 
>> On 12/21/14, 9:05 PM, "Tom Zeller" <tzeller at dragonacea.biz> wrote:
>> 
>> Gosh, I don't think attribute-release is wired into the attribute query 
>> flow in v3, or did you do that ? Or maybe I'm confused.
> 
> It's not.
> 
> If you can't selectively turn off attributes, then the set of attributes 
> being consented to is the same set that a query will return if it's done 
> in the span of a minute.
> 
> If you can only perform a query with a transient ID, then you can only 
> query immediately after SSO.
> 
> Put the two together and by default, it's not unreasonable to "consent" on 
> the front channel to the attributes that will be released on the back 
> channel.
> 
> Break either of the assumptions and it stops making sense.
> 
> -- Scott

Well then, per-attribute should not be enabled for SAML 1. Correct ? Because if ReleaseAttributes is not wired, the user's choices are not honored.


More information about the dev mailing list