Help configuring custom relying party for a relaystate url
Cantor, Scott
cantor.2 at osu.edu
Tue Aug 20 16:02:57 EDT 2013
On 8/20/13 3:30 PM, "Ian Rifkin" <irifkin at brandeis.edu> wrote:
>
>I think I may have figured it outŠI didn't include metadata for this SP,
>but they are a member of InCommon and I do look at InCommon's metadata.
I assumed so. And yes, that's what I meant. If you don't have metadata,
the SP request will error out at the IdP, making attribute release moot.
>If it helps, the SP I'm talking about it https://dmp.cdlib.org -- I see
>Ohio State is also on the list of institutions so maybe you can explain
>how you set it up for them?
We release basic directory information to all InCommon SPs, so I don't
have to do anything. People just use stuff, when the stuff only wants
identity attributes (which is 99% of them).
>Is referring to the InCommon metadata and creating a filter policy
>enough? It seems to work, but I want to make sure I'm doing things the
>right way.
When you create a policy for an SP to release attributes, the basis of
that release is authenticating the SP. The way the IdP does that is
metadata. It doesn't care what the source of metadata is. You of course
should care (not blindly importing untrusted metadata).
-- Scott
More information about the users
mailing list