Attribute Queries and AttributeQueryDescriptor in Metadata
Eric Goodman
Eric.Goodman at ucop.edu
Fri Jul 24 14:15:27 EDT 2015
On 7/23/15, 6:59 PM, "Eric Goodman" <Eric.Goodman at ucop.edu> wrote:
>>
>>Pretty sure I'm off topic here, and this may be a question with no clear answer, but in the bug description (in OpenAM's JIRA) the text says:
>>
>> "...AttributeQuery requests should be accepted from all Service Providers that are part of the same Circle of Trust as Attribute Authority is."
>I....would not use that term. It's not well defined.
FWIW, I think "Circle of Trust" is well defined in the context of a local OpenAM configuration. IIRC, it refers to a defined set of SPs and IdPs that leverage the same set of OpenAM configurations and metadata. Something like managed federations or entities descriptor groupings, but I know there's an actual configuration panel for managing "Circle of Trusts".
>In Shibboleth, you're correctly inferring that you can't really authorize release separately in those two cases,
Thanks (for this info and the rest of the comments). I recalled that v2 didn't have the ability to separate authorization, but clearly I also had a not-explicitly-posed question about whether there were new options/capabilities in v3 that you managed to uncover as well.
Have a great weekend (though I don't know if you guys really "do" weekends...),
--- Eric
More information about the dev
mailing list