How many InCommon sites will my institution show up in?

Bryan E. Wooten bryan.wooten at utah.edu
Tue Jul 2 21:56:00 EDT 2013


Just to add my 2 cents, we recently had a commercial Incommon member want
to charge us an additional $1000 a year to use Shib rather than their own
one off "pass thru" authentication scheme. (i.e. Shared secret encryption
of eppn / time stamp / vendor id).

Boggles my mindŠ

We get these SaaS vendors at a fast pace (3 in the past month), they want
custom attributes not in eduPerson, want to do some weird Idp initiated
login (but in the SAML spec) charge more and some out of band (i.e. Not
SAML) provisioning with yet another proprietary CSV file over sftp.

Don't even start on single logout or email as an identifier.

-Bryan

On 7/2/13 6:52 PM, "Tom Scavo" <trscavo at gmail.com> wrote:

>On Tue, Jul 2, 2013 at 7:54 PM, Erdos, Marlena
><marlena_erdos at harvard.edu> wrote:
>>
>> As Harvard moves toward putting up an IdP -- and getting ourselves put
>> into the InCommon metadata -- one question that has arisen is "how many
>> SPs will list  'Harvard University' as a Discovery/WAYF option
>> automatically?"
>
>There are over 1300 SPs in InCommon metadata but, contrary to popular
>belief, the vast majority of those are NOT true federated SPs (i.e.,
>cross-domain). Sorry, I don't have a number but the extremely small
>number of Research and Scholarship SPs
>(https://incommon.org/federation/info/all-sp-categories.html) leads me
>to believe that.
>
>I'd guess at most half of the small number of federated SPs in higher
>ed expose all IdPs. Precious few commercial SPs expose all IdPs.
>
>> We've noticed that some SPs (e.g. HathtiTrust and the DMP Tool) want
>>IdPs
>> to go through a distinct on-boarding procedure.
>
>Yeah, that's too bad. I counsel SPs to expose all IdPs and implement
>Federated Error Handling (https://spaces.internet2.edu/x/xa6KAQ). In
>the end, not many do, though.
>
>> Which is the more general case: automatic-boarding or explicit
>> on-boarding?   Or is there no general case? :-)
>
>My best guess is that most SPs do NOT expose all IdPs. I wish that
>were different but there you are.
>
>Tom
>--
>To unsubscribe from this list send an email to
>users-unsubscribe at shibboleth.net



More information about the users mailing list