AW: Understanding flow / federation

Ortner Nikolaus N.Ortner at fh-kaernten.at
Mon Sep 24 12:18:27 EDT 2012


> I was expecting to make, what I thought was a federation (a group of
> idP's holding each there own user base and auth method).

Well - as I understand it - a federation is more an organizational construct, call it a trust-network with policies and rules for inter-organizational collaboration with someone maintaining a huge signed file with all IdP's and SP's Metadata. Or something that sure is better described here: http://iamsect.ncl.ac.uk/deliverables/docs/federations/

If you have different user groups (students and staff?), and if you are using an exclusive IdP for each of this group - why not let the user decide?
And if you have 2 authentication mechanisms (Username/Password at IdP_1 and the-super-modern-smartcard-based-sms-secured-biometric-authentication-thing at IdP_2) - why not let the user decide?

Kind regards.



More information about the users mailing list