Administration tools for Shibboleth?
Jim Fox
fox at washington.edu
Mon Mar 11 12:03:16 EDT 2013
> * Jim Fox <fox at washington.edu> [2013-03-09 20:36]:
>> The next version of the app (testing now) supports InCommon and some
>> social logins, so the actual owner of any SP will be able to manage
>> metadata and request attributes.
>
> How are those attribute requests being turned into attribute filter
> policy rules? Someone files the SP into groups, one for each attribute
> to be granted? More local machinery then processes these groups and
> builds config rules from that?
> -peter
> --
We have a fixed filter file that provides some basic attributes to
any SP in '.washington.edu' or '.uw.edu'. That works for most local
SPs.
The web app maintains an attribute filter file for most everything else.
On any update the app writes a filter file---one clause per SP. It doesn't
attempt any grouping.
Strictly speaking, the attribute request sends email. And admin verifies
that the SP should indeed get the attribute and, by checkbox, adds that
attribute to the list of what the SP gets. A future improvement will
utilize some workflow tools to route the attribute request to the
correct people, e.g., access to student data might go the the registrar.
For the present the verification is done out-of-band.
Jim
More information about the users
mailing list