AffiliationDescriptor
Eric Goodman
Eric.Goodman at ucop.edu
Fri Jun 1 19:22:51 EDT 2018
>> The main purpose for this [AffiliationDescriptor] was to allow third party
>>signed metadata statements as an alternative to tagging entities.
>Yes, I see how that would be useful. The entity containing the
><md:AffiliationDescriptor> role could be signed by the third party.
>I asked about this because I'm searching for a scalable "no touch"
>method for local management of metadata obtained from remote sources
>(such as federations). Affiliation lists can be maintained locally and
>provisioned to IdP systems in the same way that local entity metadata
>is provisioned into a sourceDirectory of a
>LocalDynamicMetadataProvider.
This is something I had looked into as a potential mechanism for my never-dying goal of identifying SPs "approved for UCTrust data release". It's a potentially much more elegant approach than the extremely "touch" method we've batted around (i.e., repackaging federation metadata with our own entity attributes added).
Is it reasonable to use this feature as a direct entity attribute replacement? I.e., publish one AffiliationDescriptor per existing EntityAttribute? Any scaling issues with having too many AffiliationDescriptors, or with descriptors having too many members?
Supporting this would of course rely on all of my client IdPs updating to the most current release of Shib, which likely means I'll have plenty of time to consider the approach, but it does make me consider whether I want to try tilting at that windmill again on the next release.
--- Eric
More information about the dev
mailing list