[pb-iam] Extensibility of SAML 2 metadata

Keith Hazelton hazelton at wisc.edu
Wed Jun 20 13:06:59 BST 2012


Can certs for SSL be handled via the InCommon site admin tool?   --Keith
___________
On Jun 20, 2012, at 06:53:48, Keith Hazelton wrote:

> Appreciate the info, thanks Scott.
> 
> On the question of certs in SAML metadata for client authN over SSL, looking for guidance on how to do that.  I see this page:
> 
> https://spaces.internet2.edu/display/InCCollaborate/X.509+Certificates+in+Metadata
> 
> and the reference linked from there: 
> 
> X.509 Certificates in the Federation Metadata: A technical webinar presented by the InCommon Technical Advisory Committee (October 22, 2009)
> 
> Are these the right places to look for detailed how-to info?  
> 
>             --Keith
> ____________________________
> On Jun 19, 2012, at 21:37:06, Cantor, Scott wrote:
> 
>> On 6/19/12 10:09 PM, "Keith Hazelton" <hazelton at wisc.edu> wrote:
>>> 
>>> I am trying to determine if some Project Bamboo-specific entity metadata
>>> could be folded into a SAML 2 metadata document by
>>> specification-compliant extensions.
>> 
>> This is more of a saml-dev question.
>> 
>> The rule of thumb is that if you need something to drive behavior between
>> two federated systems, it's worth putting in metadata, otherwise there
>> really isn't much reason to. Even contact information at this point is a
>> questionable value proposition.
>> 
>> There's nothing in any rule that says what you can or can't put into an
>> extension, there's nothing to restrict that.
>> 
>>> Additional elements might include
>>> 
>>> - - An additional "ApplicationID" as an alias for the entityID
>> 
>> I'm not sure what that's supposed to be, but it doesn't sound like a good
>> idea.
>> 
>>> - - A cert for use in client authN over SSL
>> 
>> Unless you're talking about end users or something, that's already in
>> metadata.
>> 
>>> - - A Bamboo user identifier for the registered author of the
>>> application/entity
>> 
>> That strikes me as one of those questionable things. What purpose does it
>> serve? Documentation isn't really the point of metadata.
>> 
>> -- Scott
>> 
>> --
>> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
> 

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20120620/b75c3472/attachment.html 
-------------- next part --------------
A non-text attachment was scrubbed...
Name: PGP.sig
Type: application/pgp-signature
Size: 535 bytes
Desc: This is a digitally signed message part
Url : http://shibboleth.net/pipermail/users/attachments/20120620/b75c3472/attachment.bin 


More information about the users mailing list