Not-so-hypothetically

David Langenberg davel at uchicago.edu
Thu Mar 8 18:10:06 GMT 2012


On Thu, Mar 8, 2012 at 11:05 AM, Keith Hazelton <hazelton at doit.wisc.edu>wrote:

> On Thu, 2012-03-08 at 12:59 -0500, Chad La Joie wrote:
> > Hey Keith,
> >
> > I'm not quite sure what you're asking.  You seem to be suggesting that
> > passing a given entitlement value through would be bad but that passing
> > affiliation values isn't.  I'm not sure I see any difference.
> >
> > If you're interested in a full SAML solution, the answer is fairly easy.
> >  You delegate through each tier an either the assertion contains
> > attributes targeted to the SP or the SP queries for them.  Then no one
> > gets to see data they weren't supposed to.
>
> But that's ECP, right? and too few IdPs support ECP endpoints for our
> case.  Or is there a non-ECP way to do this?
>

Well, it's more the P part of ECP.  I imagine you'd see an increase in
endpoints if the project completed implementation of ECP, and more SPs
demanded it.

Dave

-- 
David Langenberg
Identity Management
The University of Chicago
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20120308/e49eb663/attachment.html 


More information about the users mailing list