AttributeValueMatchesShibMDScopeFunctor.cpp ?

Peter Schober peter.schober at univie.ac.at
Mon Feb 24 11:02:02 EST 2014


* Cantor, Scott <cantor.2 at osu.edu> [2014-02-24 16:36]:
> On 2/24/14, 10:26 AM, "Peter Schober" <peter.schober at univie.ac.at> wrote:
> >It's defined to be single-valued and as such can't be replaced with
> >simply extracting shibmd:Scope from SAML metadata in the SP instead
> >(as that would potentially result in multiple values; though changing
> >the attribute to become multi-valued is not inconcievable itself.)
> 
> I'd be more concerned about not having a 1:1 mapping of domain to
> "organization with contract", but that's a larger discussion.

ACK

> >Would it make sense (and would the project consider including a rule
> >for schacHomeOrganization to the default attribute-policy.xml) to add
> >a copy of the AttributeScopeMatchesShibMDScope functor that matches an
> >attribute value (string) against shibmd:Scope, i.e. to create an
> >AttributeValueMatchesShibMDScope rule?
> 
> Two parts to the question:
> 
> - I have no objection to adding any default attributes people want as long
> as they're standardized in an appropriate way and not just ad hoc.

It is (from proper OIDs to an RFC defining the URN to ownership),
though the spec needs some cleanup and governence needs to be
improved.

> - Having a filter functor like that would be fine, modulo that I can't
> really say when a 2.6 might emerge.

Thanks fine, thanks.
-peter


More information about the dev mailing list