Extensibility of SAML 2 metadata

Cantor, Scott cantor.2 at osu.edu
Wed Jun 20 03:37:06 BST 2012


On 6/19/12 10:09 PM, "Keith Hazelton" <hazelton at wisc.edu> wrote:
>
>I am trying to determine if some Project Bamboo-specific entity metadata
>could be folded into a SAML 2 metadata document by
>specification-compliant extensions.

This is more of a saml-dev question.

The rule of thumb is that if you need something to drive behavior between
two federated systems, it's worth putting in metadata, otherwise there
really isn't much reason to. Even contact information at this point is a
questionable value proposition.

There's nothing in any rule that says what you can or can't put into an
extension, there's nothing to restrict that.

>Additional elements might include
>
>- - An additional "ApplicationID" as an alias for the entityID

I'm not sure what that's supposed to be, but it doesn't sound like a good
idea.

>- - A cert for use in client authN over SSL

Unless you're talking about end users or something, that's already in
metadata.

>- - A Bamboo user identifier for the registered author of the
>application/entity

That strikes me as one of those questionable things. What purpose does it
serve? Documentation isn't really the point of metadata.

-- Scott



More information about the users mailing list