Help configuring custom relying party for a relaystate url

Ian Rifkin irifkin at brandeis.edu
Tue Aug 20 14:33:40 EDT 2013


Hi,

That isn't possible unless you enabled anonymous RP support. Without
> metadata it won't work.
>

I see one line in my RP config that mentions "anonymous:"
 <rp:AnonymousRelyingParty provider="
https://shibboleth.brandeis.edu/idp/shibboleth"
defaultSigningCredentialRef="IdPCredential"/>

So I guess I have enabled anonymous RP support. Is that something that is
there by default? Regardless…

If you don't care about controlling which SPs actually use the IdP, then
> you don't necessarily need metadata
>

This gets to the heart of my question. *Should* I be concerned?

What do you mean by SPs that "actually use the IdP"? If I didn't release an
attribute to a particularly anonymous SP's entityID then what would happen?

but then there are attribute release considerations.


What are the attribute release considerations? I don't think I release
attributes to unknown SPs -- and like I said, I used the "anonymous" SP's
entityID to release an attribute that they need (which I'm hoping isn't
releasing

Using the aacli.sh bin to test if I use the anonymous SP's entityID I see
the attribute I released to them. If I type in jibberish for the requester
then it just returns "No attribute statement." I guess this is why I'm
confused -- what will creating metadata improve/fix/prevent?

Thanks again,
Ian
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130820/7515ee2d/attachment.html 


More information about the users mailing list