CAS Service Registry

Marvin Addison marvin.addison at gmail.com
Thu Apr 9 13:50:50 EDT 2015


>
> Maybe this ship has sailed, but after using the PatternServiceRegistry for
> a while, I find myself wishing that this configuration was expressed via
> the SAML metadata.
>

I'm absolutely open to enhancements and extensions. That said, there's a
fundamental problem for which I don't see a solution w/r/t an
metadata-based implementation. The service registry model provides a
one-to-many registry, which is absolutely vital for most CAS deployments,
and I don't see how to implement something similar with SAML metadata.

Perhaps where I'm getting hung up on the equivalent model under SAML
metadata is using service URLs for entity IDs. I suppose we could create an
arbitrary identifier that functions like a group name and each entity in
that case would be composed of multiple "services", but that's a
fundamentally different model than anything I've ever seen. I simply don't
know enough about SAML metadata to understand what my options are. I'm open
to any solution that supports the one-to-many requirement.

M
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/dev/attachments/20150409/9dae4998/attachment.html 


More information about the dev mailing list