Hostname patch for Shibboleth IDP 2.4.0
Nate Klingenstein
ndk at internet2.edu
Thu Nov 21 10:49:36 EST 2013
I'd be in favor of removing guessing if there were a default, global place to configure scope, with the scope attribute being considered an override of that default.
Asking users to go in and tinker with many individual Attribute definitions is something I consider to be a nuisance for some deployers. Usually the guess is not far off.
The two-or-less domain components error messaging still needs to be fixed(well, added).
________________________________________
From: users-bounces at shibboleth.net <users-bounces at shibboleth.net> on behalf of Martin Haase <Martin.Haase at DAASI.de>
Sent: Thursday, November 21, 2013 14:48
To: Shib Users
Subject: Re: Hostname patch for Shibboleth IDP 2.4.0
If you give a hostname with less than two dots in the build script, e.g.
"testidp.intra" or "localhost" (arguably insensible, but whatever), the
build fails in the first place. No way to get a functional IDP home
directory except patching build.xml. What about removing scope guessing
from the installer in the first place? attribute-resolver.xml needs to
be edited anyway for doing anything usable with the IdP...
Am 21.11.2013 13:26, schrieb Peter Schober:
> * Guest, Simon <simon.guest at agresearch.co.nz> [2013-11-19 23:19]:
>> Without this patch, generating the scope from the hostname fails, as
>> it only expects a single dot in the scope.
> Note that while will reduce the number of incorrectly guessed scopes
> for new installes (esp. for ccTLDs with heirarchies in them, such as
> co.nz or ac.uk) the scope cannot be determined correctly
> automatically, period.
> It might be completely different from the IdP's FQDN, or the new
> domain component from your patch might actually be
> unwanted/nonsensical to have in a scope (e.g. you might want to have
> the IdP in the test. zone issue scopes in the common domain).
>
> So it is fully expected and intended for people to manually adjust
> the scope in the auto-generated metadata/idp-metadata.xml file after
> installation. Much later, maybe, once they had the chance to read up
> on scopes and what it means.
> -peter
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
--
Dr. Martin Haase, Solutions Engineer
DAASI International GmbH
Europaplatz 3
D-72072 Tübingen
Germany
phone: +49 7071 407109-6
fax: +49 7071 407109-9
email: martin.haase at daasi.de
web: www.daasi.de
Sitz der Gesellschaft: Tübingen
Registergericht: Amtsgericht Stuttgart, HRB 382175
Geschäftsleitung: Peter Gietz
More information about the users
mailing list