Help configuring custom relying party for a relaystate url

Cantor, Scott cantor.2 at osu.edu
Tue Aug 20 16:02:57 EDT 2013


On 8/20/13 3:30 PM, "Ian Rifkin" <irifkin at brandeis.edu> wrote:
>
>I think I may have figured it outŠI didn't include metadata for this SP,
>but they are a member of InCommon and I do look at InCommon's metadata.

I assumed so. And yes, that's what I meant. If you don't have metadata,
the SP request will error out at the IdP, making attribute release moot.

>If it helps, the SP I'm talking about it https://dmp.cdlib.org -- I see
>Ohio State is also on the list of institutions so maybe you can explain
>how you set it up for them?

We release basic directory information to all InCommon SPs, so I don't
have to do anything. People just use stuff, when the stuff only wants
identity attributes (which is 99% of them).

>Is referring to the InCommon metadata and creating a filter policy
>enough? It seems to work, but I want to make sure I'm doing things the
>right way.

When you create a policy for an SP to release attributes, the basis of
that release is authenticating the SP. The way the IdP does that is
metadata. It doesn't care what the source of metadata is. You of course
should care (not blindly importing untrusted metadata).

-- Scott




More information about the users mailing list