[pb-iam] Extensibility of SAML 2 metadata
Keith Hazelton
hazelton at wisc.edu
Wed Jun 20 13:06:59 BST 2012
Can certs for SSL be handled via the InCommon site admin tool? --Keith
___________
On Jun 20, 2012, at 06:53:48, Keith Hazelton wrote:
> Appreciate the info, thanks Scott.
>
> On the question of certs in SAML metadata for client authN over SSL, looking for guidance on how to do that. I see this page:
>
> https://spaces.internet2.edu/display/InCCollaborate/X.509+Certificates+in+Metadata
>
> and the reference linked from there:
>
> X.509 Certificates in the Federation Metadata: A technical webinar presented by the InCommon Technical Advisory Committee (October 22, 2009)
>
> Are these the right places to look for detailed how-to info?
>
> --Keith
> ____________________________
> On Jun 19, 2012, at 21:37:06, Cantor, Scott wrote:
>
>> On 6/19/12 10:09 PM, "Keith Hazelton" <hazelton at wisc.edu> wrote:
>>>
>>> I am trying to determine if some Project Bamboo-specific entity metadata
>>> could be folded into a SAML 2 metadata document by
>>> specification-compliant extensions.
>>
>> This is more of a saml-dev question.
>>
>> The rule of thumb is that if you need something to drive behavior between
>> two federated systems, it's worth putting in metadata, otherwise there
>> really isn't much reason to. Even contact information at this point is a
>> questionable value proposition.
>>
>> There's nothing in any rule that says what you can or can't put into an
>> extension, there's nothing to restrict that.
>>
>>> Additional elements might include
>>>
>>> - - An additional "ApplicationID" as an alias for the entityID
>>
>> I'm not sure what that's supposed to be, but it doesn't sound like a good
>> idea.
>>
>>> - - A cert for use in client authN over SSL
>>
>> Unless you're talking about end users or something, that's already in
>> metadata.
>>
>>> - - A Bamboo user identifier for the registered author of the
>>> application/entity
>>
>> That strikes me as one of those questionable things. What purpose does it
>> serve? Documentation isn't really the point of metadata.
>>
>> -- Scott
>>
>> --
>> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20120620/b75c3472/attachment.html
-------------- next part --------------
A non-text attachment was scrubbed...
Name: PGP.sig
Type: application/pgp-signature
Size: 535 bytes
Desc: This is a digitally signed message part
Url : http://shibboleth.net/pipermail/users/attachments/20120620/b75c3472/attachment.bin
More information about the users
mailing list