Should IDP/SP metadata contain a roleDescriptor tag?

Tom Scavo trscavo at gmail.com
Mon Jul 9 16:23:45 EDT 2012


On Mon, Jul 9, 2012 at 3:10 PM, Wessel, Keith William
<kwessel at illinois.edu> wrote:
> Following up on this, I think that Siteminder is being pickier than the SAML standards, and I'm looking for confirmation of that.
>
> There are two ways to make Siteminder happy with recognizing an SP as SAML 2.0 compliant. You can either, as you described earlier, Tom, use a roleDescriptor tag that explicitly states that the entity uses the SAML 2.0 standard

Well, I didn't mean to imply that, but it's not a problem.

> or you can specify the supported protocols in increasing numerical order as attributes to the spSSODescriptor tag. That is if you specify the supported protocols in the order ot 1.1, 2.0, it'll recognize it as 2.0. If you specify it as 2.0, 1.1, it'll only recognize it as 1.1.

I don't see any such requirement in the spec, so the ball is in their
court to provide evidence to the contrary.

> Our metagen.sh script is creating metadata that lists the protocols in decreasing numerical order, but the Shibboleth IDP is fine with that. The Siteminder IDP is not.
>
> Is the Shib IDP just extra forgiving, or is Siteminder not following the standards?

I don't see anything in the spec that requires a particular ordering.
That said, InCommon metadata follows that pattern, perhaps because
it's a "natural" ordering, but like I said, I don't think it's
strictly required.

Tom


More information about the users mailing list