Not-so-hypothetically
David Langenberg
davel at uchicago.edu
Thu Mar 8 18:10:06 GMT 2012
On Thu, Mar 8, 2012 at 11:05 AM, Keith Hazelton <hazelton at doit.wisc.edu>wrote:
> On Thu, 2012-03-08 at 12:59 -0500, Chad La Joie wrote:
> > Hey Keith,
> >
> > I'm not quite sure what you're asking. You seem to be suggesting that
> > passing a given entitlement value through would be bad but that passing
> > affiliation values isn't. I'm not sure I see any difference.
> >
> > If you're interested in a full SAML solution, the answer is fairly easy.
> > You delegate through each tier an either the assertion contains
> > attributes targeted to the SP or the SP queries for them. Then no one
> > gets to see data they weren't supposed to.
>
> But that's ECP, right? and too few IdPs support ECP endpoints for our
> case. Or is there a non-ECP way to do this?
>
Well, it's more the P part of ECP. I imagine you'd see an increase in
endpoints if the project completed implementation of ECP, and more SPs
demanded it.
Dave
--
David Langenberg
Identity Management
The University of Chicago
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20120308/e49eb663/attachment.html
More information about the users
mailing list