Franchise access being authenticated by our Shibboleth IdP

Cantor, Scott cantor.2 at osu.edu
Thu Feb 23 16:20:48 GMT 2012


> I'm not sure what you mean here, can you explain further in layman's terms?

Affiliations are not about services, they're only about users. A student is a student because he's a student, not because a service is saying "if you want to get access, tell me you're a student". It's a fact of identity that should be storable in a directory or database and then expressed uniformly to all services.

Using them for authorization is tricky, and arguably a bad idea in many cases. Misusing them by telling IdPs to "assert an affiliation regardless of its truth as a substitute for an entitlement" is also a bad idea, and that one creates problems for IdPs that already support affiliation in the manner intended.

In fact, the recent thread on MACE-Dir about this exact issue led one person to send a somewhat hyperbolic, probably not entirely serious, diatribe about that exact point. "Don't use them, because then people will start having to lie about affiliation in order to get people access to things".

The other comments in the thread were in the same vein as my point. If you rely on this sort of attribute for authorization, then the exceptions bite you in the butt later because it's *not* really students that get access it's "the set of people that get access" that get access. At  a minimum, you end up having to combine affiliation with something else anyway.

-- Scott



More information about the users mailing list