AttributeScopeMatchesShibMDScope

Cantor, Scott cantor.2 at osu.edu
Thu Oct 27 15:21:59 BST 2011


On 10/27/11 8:02 AM, "Kristof Bajnok" <bajnokk at niif.hu> wrote:
>
>what's the intention, should AttributeScopeMatchesShibMDScope evaluate
>to true when there is no shibmd:Scope extension in the
>IdPSSODescriptor's metadata?

If there are no extensions present and you still apply that rule, then
you're asking it to filter out the results. If you don't want to use the
extension, don't use the rule (or don't apply it to those attributes or
IdPs at least).

> According to one of our recent issues, if
>the other party (mis?)places the Scope element into the
>EntityDescriptor, it seems to evaluate to false. If I remember
>correctly, it was the same when there was no Scope element.

It handles the extension regardless of at which level it's placed. In
retrospect we wished it would have been entity-level, but it was too late
to do much about it. If you had all 2.x SPs, it should be possible to just
place it at entity level.

So, no, putting it there is not the same as not having it, unless the SP
is badly out of date (as in probably not even the last 1.3 release).

>I would think that default SP configuration shouldn't require the
>proprietary metadata extensions favouring interoperability.

Of course, defaults are always open to discussion. If people felt the
default shouldn't be to apply a rule that relies on an extension, that's
open for debate. But I think the community has generally felt it was
better to have it and have people remove it than the opposite.

>Anyway, it'd be great if this rule would be documented in the wiki.

Have at it. Some things just seem obvious when writing docs, so they don't
come to mind.

-- Scott



More information about the users mailing list