Getting list of all configured IDPs from Shibboleth SP
Chad La Joie
lajoie at itumi.biz
Sat Feb 4 00:01:27 GMT 2012
On Fri, Feb 3, 2012 at 18:56, Tom Scavo <trscavo at gmail.com> wrote:
> So people feel more comfortable modifying kernel policy than making a
> JSONP call at the application level? Uh, okay.
Essentially opening a firewall on a port is a far different thing than
blindly accepting remote code to execute locally.
> So I guess I'll just come right out and ask: If InCommon were to offer
> a trusted JSONP endpoint for retrieving JSON metadata, would you use
> it? That's a real question, and yes, private e-mail is fine. The more
> responses I receive, the closer this gets pushed to the front burner.
No, it doesn't even belong on the dev list as it has nothing to do
with Shibboleth. But since you asked, no I would not execute remotely
hosted, unverifiable code.
--
Chad La Joie
www.itumi.biz
trusted identities, delivered
More information about the users
mailing list