One idp application serving as two idps (with different entityIDs)
Lukas Hämmerle
lukas.haemmerle at switch.ch
Fri Feb 12 05:33:50 EST 2016
On 12.02.16 02:38, Cantor, Scott wrote:
>> Aside from a new Function-based approach: If the desired task is to
>> select a RelyingPartyConfiguration (including responderId) based on
>> something other than the entityID, like info in the SAML request,
>> couldn't this be done today pretty easily by just attaching
>> different activationCondtion(s) to the RPC, as a
>> Predicate<ProfileRequestContext>.
>
> I guess it would work, yes. A little weird, wouldn't scale all that
> well depending on the number of possibilities, you're basically
> expanding a table of mappings out into separate overrides for every
> row of the table.
Thanks :-) Given that the number of responderIds (entitIDs) would be
limited (to a few dozens) and that we probably won't need separate
Overrides for specific SPs this sounds like an interesting approach to
start with.
So, I'll study the Activation Conditions on
https://wiki.shibboleth.net/confluence/display/IDP30/ActivationConditions
Best Regards
Lukas
--
SWITCH
Lukas Hämmerle, Central Solutions
GÉANT Project Task Leader "Enabling Users"
Werdstrasse 2, P.O. Box, 8021 Zurich, Switzerland
phone +41 44 268 15 05, direct +41 44 268 15 64
lukas.haemmerle at switch.ch, http://www.switch.ch
More information about the dev
mailing list