Extensibility of SAML 2 metadata
Cantor, Scott
cantor.2 at osu.edu
Wed Jun 20 18:42:47 BST 2012
On 6/20/12 1:36 PM, "Keith Hazelton" <hazelton at wisc.edu> wrote:
>
>So for certs for non-SAML entity client auth purposes, is there a
>metadata spec-compliant way to add another descriptor element different
>from the current ones?
Whether it's SAML or not isn't the issue, it's what the functional role
is. If the thing is an IdP or an SP, then the existing roles are usually
appropriate. If not, not.
>For argument's sake, something like
>
><BambooAppDescriptor .... >
>...
></BambooAppDescriptor>
You can't define new role elements, only new schema types to plug into
<RoleDescriptor> via xsi:type.
Very early spec example:
http://docs.oasis-open.org/security/saml/Post2.0/sstc-saml-metadata-ext-que
ry-cs-01.pdf
-- Scott
More information about the users
mailing list