WS-Federation resource provider relationship with our IdP

Cantor, Scott cantor.2 at osu.edu
Fri Mar 28 15:20:57 EDT 2014


On 3/28/14, 2:43 PM, "Tom Scavo" <trscavo at gmail.com> wrote:

>And speaking of metadata issues, AD FS has its share of those. It's
>unlikely their AD FS SP will be able to directly consume any metadata
>file you provide (maybe FEMMA will work, I don't know), which means
>you're trapped when it comes time to migrate a certificate in IdP
>metadata, or something along those lines.

I took the OP's description to mean they'd likely be supplying their own
metadata, and basic SAML metadata, even from a Shibboleth IdP or SP pretty
much works fine.

As far as migrating a key, sure, but that doesn't work with any commercial
products, so ADFS is no worse. And obviously using a non-SAML protocol
won't improve matters in any of these respects.

-- Scott




More information about the dev mailing list