SAML2 AttributeService endpoints
Tom Scavo
trscavo at gmail.com
Sun Mar 30 12:04:05 EDT 2014
There are 181 SAML2 AttributeService endpoints in InCommon metadata.
This is probably because at one time we included a SAML2
AttributeService endpoint by default when a new IdP was created via
the Federation Manager. We don't do this any more but I'm afraid the
damage is done.
As I understand it, a SAML2 AttributeService endpoint can lead to
unnecessary queries and even spurious errors at the SP. I think I
understand the conditions under which a Shibboleth SP will make an
unnecessary attribute query but can this be avoided at the SP? I
suspect it can't.
Which leads me to my main question: What do I tell IdP administrators?
Can I tell them to remove a SAML2 AttributeService endpoint in all
cases? Is there something in the Shibboleth IdP configuration that
admins can look for?
Thanks,
Tom
More information about the dev
mailing list