Jetty deployment

Peter Schober peter.schober at univie.ac.at
Mon Sep 29 19:53:33 EDT 2014


* Ian Young <ian at iay.org.uk> [2014-09-16 19:58]:
> I think the raw proportion is interesting, but it's hard to get from
> there to how many IdPs *only* access SAML 2 SPs. It just takes one
> SP being in the SAML 1 only camp to potentially cause problems for
> any given IdP. In the UK, because the publisher use case is much
> more prevalent than I understand it to be for InCommon, something in
> that 8% is almost certainly used by almost every IdP.
[...]
> I'd love to get to the point where disabling back-channel by default
> was practical. It causes pain we should be able to do without, at
> least until the next reason to use back-channel becomes prevalent.

But those same publishers usually only recieve ePSA (in the UK) or the
common-lib-terms ePE (elsewhere), plus maybe ePTID.
Shouldn't be a hard sell recommending to push those over the browser.
(It's not like there are dozens of exploits waiting in your browser
only to learn your ePTID for ScienceDirect.)
IMHO the UKf recommendations could very well be adapted here, making
back-channel actually unnecessary for IDPs following those
recommendations, today.

Looking at this from another angle: From what I read on the users list
hardly any "SaaS" vendor seems to support encryption /and/ IDPs are
usually required to send userid or email address (as unspecified
NameID, of course). The point being that institutions don't seem to
have issues with doing that.
So why fret about the case where the SP not even requires PII?
-peter


More information about the dev mailing list