Getting list of all configured IDPs from Shibboleth SP

Chad La Joie lajoie at itumi.biz
Sat Feb 4 00:01:27 GMT 2012


On Fri, Feb 3, 2012 at 18:56, Tom Scavo <trscavo at gmail.com> wrote:
> So people feel more comfortable modifying kernel policy than making a
> JSONP call at the application level? Uh, okay.

Essentially opening a firewall on a port is a far different thing than
blindly accepting remote code to execute locally.

> So I guess I'll just come right out and ask: If InCommon were to offer
> a trusted JSONP endpoint for retrieving JSON metadata, would you use
> it? That's a real question, and yes, private e-mail is fine. The more
> responses I receive, the closer this gets pushed to the front burner.

No, it doesn't even belong on the dev list as it has nothing to do
with Shibboleth.  But since you asked, no I would not execute remotely
hosted, unverifiable code.

-- 
Chad La Joie
www.itumi.biz
trusted identities, delivered


More information about the users mailing list