Configuration of IdP with Delegation extension
Cantor, Scott
cantor.2 at osu.edu
Fri Apr 13 18:19:54 BST 2012
On 4/13/12 1:02 PM, "Karla Borecky" <kborecky at smith.edu> wrote:
>
>This concerned me. How does this affect all of the SPs I am talking to
>now that *aren't* delegation-aware?
I'm not aware that has any effect at all, but I suppose it's just a
question of not wanting to introduce unneeded code into existing
transactions.
>This implies that delegation might now has its own profile - yay - but
>this change is not reflected in the README file on how to configure
>the IdP.
It's implied. If you don't want to convert the existing handlers, then you
add the new one, give it a dedicated profile path, and then make sure that
the SSO service in the metadata you hand out reflects which one you expect
the recipient of the metadata to use.
It's kind of a giant hassle to be creating special metadata for different
SPs, so honestly, I don't think it makes sense to do it. The security
controls are explicitly based on enabling use of the delegation feature by
particular RPs. You don't get security by just hiding the fact that the
second endpoint happens to be there, so it really is just a question of
comfort level running the subclass for everybody, or not.
-- Scott
More information about the users
mailing list