Attribute Queries and AttributeQueryDescriptor in Metadata

Cantor, Scott cantor.2 at osu.edu
Fri Jul 24 14:22:27 EDT 2015


On 7/24/15, 2:15 PM, "dev on behalf of Eric Goodman" <dev-bounces at shibboleth.net on behalf of Eric.Goodman at ucop.edu> wrote:
>
>FWIW, I think "Circle of Trust" is well defined in the context of a local OpenAM configuration.

Ok, didn't know that. It's an old Liberty term that I thought had died out.

>Thanks (for this info and the rest of the comments). I recalled that v2 didn't have the ability to separate authorization, but clearly I also had a not-explicitly-posed question about whether there were new options/capabilities in v3 that you managed to uncover as well.

I didn't implement the second role, as I said, and if I had, I don't know if it would have occurred to me at the time to think about the implications as deeply as I should have.

But there are a lot of knobs. For example, you could also selectively enable the query profile outright for a particular RP so even if we honored both roles in every request, that wouldn't imply you could make a query if you had an SP role anyway.

-- Scott



More information about the dev mailing list