Extensibility of SAML 2 metadata

Keith Hazelton hazelton at wisc.edu
Wed Jun 20 18:49:52 BST 2012


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Jun 20, 2012, at 12:42:47, Cantor, Scott wrote:

> On 6/20/12 1:36 PM, "Keith Hazelton" <hazelton at wisc.edu> wrote:
>> 
>> So for certs for non-SAML entity client auth purposes, is there a
>> metadata spec-compliant way to add another descriptor element different
>> from the current ones?
> 
> Whether it's SAML or not isn't the issue, it's what the functional role
> is. If the thing is an IdP or an SP, then the existing roles are usually
> appropriate. If not, not.

Then I think it's not appropriate.  Not all Bamboo apps will be packaged as SPs.

So that suggests creative stealing, er adaptation, of good ideas from the SAML metadata spec and coming up with our own Bamboo Federation-specific metadata spec for this kind of thing.  Bamboo, of course, will have classic SAML metadata files as well.

        So, taking this topic off the Shib Users list as of now,   --Keith
_____________________
> 
>> For argument's sake, something like
>> 
>> <BambooAppDescriptor ....  >
>> ...
>> </BambooAppDescriptor>
> 
> You can't define new role elements, only new schema types to plug into
> <RoleDescriptor> via xsi:type.
> 
> Very early spec example:
> 
> http://docs.oasis-open.org/security/saml/Post2.0/sstc-saml-metadata-ext-que
> ry-cs-01.pdf
> 
> -- Scott
> 
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net

-----BEGIN PGP SIGNATURE-----
Version: GnuPG/MacGPG2 v2.0.18 (Darwin)
Comment: GPGTools - http://gpgtools.org

iQEcBAEBAgAGBQJP4g1BAAoJEPXbVHOlscTvUngH/3vl699yrg1nWhRwgXPBvLRV
2jYojtAYJzQkh37/xbFcGSAB+u49WTJVtMDm5wRQbHG+pRWc09Feb/UTwwafZp6v
GJby4QKFLFYNc8I03HKx3LkP26f3DC38CKqMEvHUYAtLFqjpt+atTP0WtDc+g3lq
7T5JlMOm0Hl/4kbcNyuF4rLoW3vj9E0Y9SAXBYB6rLVCMW5eQnbQGjM3Zdfa3bw1
EygavwmTliV6WNLYGkGis+j2jJCwl4l5SS6uvHdDxrtCXRk1pZWTdcOM6EwcAouP
nCEI7XdGNQVktzxSNW4zL98nVFJHUrA/BI+PWNTyKk23zdT9P5RmmPZ57nsGomo=
=6b+F
-----END PGP SIGNATURE-----


More information about the users mailing list