F-TICKS addition

Cantor, Scott cantor.2 at osu.edu
Fri Nov 6 10:12:19 EST 2015


On 11/6/15, 10:05 AM, "dev on behalf of Chris Phillips" <dev-bounces at shibboleth.net on behalf of Chris.Phillips at canarie.ca> wrote:



>Thanks Scott,
>
>I've done a pass on this and added a comment or two into the ticket:
>- idp.properties is the file for the settings NOT idp.ini (my bad in the
>original write up & apologies for that)
>- clarification on the placement of the hashed user map item in the
>various extractor maps is desired

I need to understand under what circumstances you could have been getting duplicates, but I don't have a way to prevent them. I would also, I guess, have to suggest that I'm not sure this actually is going to work, because auditing is not limited to a single profile. These records aren't going to get output only on SSO, unless you actually block the all other auditing. These records will even be output on *errors* too, not just success.

So I'm now questioning whether I should have done this. Or if we do, if a bunch of other settings to block auditing in all the other cases would be needed.

It may just not fit as an audit mechanism, might need to be deferred and then added as a dedicated feature of specific profiles.

Basically, I need guidance here, but I'm thinking I may need to roll this back.

>Is it safe for to presume that:
>- These new values will be recognized by the Shib installer if provided on
>the command line like any other -Didp.* property?
>- That the settings are portable in this manner across both windows and
>non windows installations?

Yes.

>A generic question about invoking the Shibboleth installer:
>Does the installer filter any -Didp.* property or can anything be passed
>in and then expected to be placed into the idp.properties file?

I wasn't aware anything ever got placed into that file by the installer, but I wouldn't know.

-- Scott



More information about the dev mailing list