RequestedAttributes in SP metada

Cantor, Scott cantor.2 at osu.edu
Mon Dec 30 10:16:26 EST 2013


On 12/30/13, 10:04 AM, "Ian Young" <ian at iay.org.uk> wrote:
>
>In other words, it appears to be looking in the peer's (SP's) metadata
>for an attribute authority descriptor... which won't be present. I don't
>see any evidence that it is looking at the SP's RequestedAttribute
>information at all.

It predates even thinking about that part of metadata.

> This may be because it's possible to have many of those, but I will have
>to leave it to someone who knows that code better to be definitive.
>
>(Scott has replied already saying that this code isn't operational, but
>I'm not sure if the above is new information.)

I haven't looked at it lately, but I am aware of the fact that there are
methods to obtain attribute ID collections for input to the resolver that
have never been operational and don't return anything. If the code base
wasn't headed for maintenance mode I would have cleaned that up, but since
it's being thrown out, I left it alone. The AttributeAuthority layer of
classes in the code are very questionable in many areas and aren't being
ported over.

It is possible in isolated cases to tell the resolver to return only
specific attributes but that isn't used at all in any of the code we ship.
It has been used by people calling the resolver from inside a custom login
handler, to return assurance related attributes.

None of this is relevant to anybody deploying an IdP and doing basic
attribute exchange.

-- Scott




More information about the users mailing list