Administration tools for Shibboleth?

Jim Fox fox at washington.edu
Sat Mar 9 14:32:26 EST 2013



On Mar 9, 2013, at 3:11 AM, Peter Schober wrote:

> * Jim Fox <fox at washington.edu> [2013-03-08 19:12]:
>> We use a web app and some local authorization apis to provide
>> self-serve and automatic update of local metadata (for SPs that
>> are not in InCommon), and attribute release policies.
> 
> Note that there are other aspects of IdP administration besides local
> metadata registration practices.
> 
>> We don't hand edit any files.
> 
> How do you enable new SPs available via the federation or bilateral
> agreements?
> -peter

We augment the DNS ownership API with our group service.  A group is associated with a DNS name and members of the group are considered owners.  The group service supports eppn and some social identities.  At present, one of our people acts as admin and manages the metadata and attribute requests.  

For bilateral SPs the web app can get most metadata from the SP's Metadata endpoint.  Our guy then fills in the name, description, etc.

The attribute request capability is available to any SP in InCommon or in local metadata. 

The next version of the app (testing now) supports InCommon and some social logins, so the actual owner of any SP will be able to manage metadata and request attributes.

Jim 


More information about the users mailing list