Extensibility of SAML 2 metadata

Tom Scavo trscavo at gmail.com
Wed Jun 20 18:45:59 BST 2012


On Wed, Jun 20, 2012 at 1:36 PM, Keith Hazelton <hazelton at wisc.edu> wrote:
>
> So for certs for non-SAML entity client auth purposes, is there a metadata spec-compliant way to add another descriptor element different from the current ones?  For argument's sake, something like
>
> <BambooAppDescriptor ....  >
> ...
> </BambooAppDescriptor>

I assume you're talking about a custom role descriptor (in lieu of
IDPSSODescriptor or SPSSODescriptor). If so, the answer is yes, you
can create a custom role descriptor. For example, Scott and I created
one a long time ago for the purposes of standalone attribute query:

https://wiki.oasis-open.org/security/SstcSamlMetadataExtQuery

Hope this helps,
Tom


More information about the users mailing list