SAML2 AttributeService endpoints

Tom Scavo trscavo at gmail.com
Sun Mar 30 12:04:05 EDT 2014


There are 181 SAML2 AttributeService endpoints in InCommon metadata.
This is probably because at one time we included a SAML2
AttributeService endpoint by default when a new IdP was created via
the Federation Manager. We don't do this any more but I'm afraid the
damage is done.

As I understand it, a SAML2 AttributeService endpoint can lead to
unnecessary queries and even spurious errors at the SP. I think I
understand the conditions under which a Shibboleth SP will make an
unnecessary attribute query but can this be avoided at the SP? I
suspect it can't.

Which leads me to my main question: What do I tell IdP administrators?
Can I tell them to remove a SAML2 AttributeService endpoint in all
cases? Is there something in the Shibboleth IdP configuration that
admins can look for?

Thanks,

Tom


More information about the dev mailing list