SP-SP (or IdP-IdP) metadata exchange?

Don Faulkner donf at uark.edu
Tue Jul 17 18:46:23 EDT 2012


Two similar questions:

Is there ever a reason for two or more SP systems to need to have
knowledge of each other?
Is there ever a reason for two or more IdP systems to need to have
knowledge of each other?

I ask because I'm building the tools that construct our campus metadata
as a campus-wide "mini federation." I've read at least one web page (I
think out of nordu.net) that described building separate metadata files
for the IdP and SP systems in the federation. I guess that makes some
sense for a large federation, but for a campus with one IdP, I don't see
a reason to do it. That leaves me with a couple of options:

1. Put all SP metadata into a EntitiesDescriptor, have the IdP load that
periodically. Have all SP load the IdP metadata only.
2. Put all metadata (IdP + multiple SP) into a single file and have all
systems load that periodically.

In either case I think the IdP/SP production metadata list will look
like this:
Campus-Local-Metadata (via option 1/2 above),
Non-Federated systems (google, et. al.), as a separate
EntitiesDescriptor, unsigned.
InCommon Federation
Any other federations we peer with (currently only Great Plains)

I asked my original question because I wasn't sure if SP's (or IdP's)
ever directly communicate with each other, or if it's always SP<=>IdP. I
can think of good reasons for SP's to be able to, but I'm not sure if
the protocol supports it.

-- 
me Don Faulkner, CISSP | IT Security <http://its.uark.edu/> at the
University of Arkansas <http://www.uark.edu/>
contact>> donf at uark.edu <mailto:donf at uark.edu> | +1 (479) 575-2905
connect>> uarkITS on Facebook <http://www.facebook.com/uarkITS> | @uaits
<http://twitter.com/uaits> | @dfaulkner <http://twitter.com/dfaulkner>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20120717/f50403d8/attachment-0001.html 


More information about the users mailing list