Guidance for app owners: got any? (i.e. "things to think about" before you develop/deploy)
Erdos, Marlena
marlena_erdos at harvard.edu
Mon Sep 23 17:26:40 EDT 2013
Tom,
First off, thank you for the response.
> Part of the difficulty in responding to your request, Marlena, is that
the purpose and scope of the SP matters.
>
I entirely agree. That's why I'm looking to ask questions that would help
an app owner thing through their access issues rather than provide "one
size fits all" advice.
And that's why I'm looking to provide examples that might let an app owner
say, "Oh, that scenario is like mine."
> InCommon is focused on
cross-domain SPs (a term I've used before, if you'll recall) but for
the most part, on-campus SPs are out of scope.
>
As it turns out, a lot of apps within Harvard have a cross-domain aspect
because we have schools that have their own IT departments in addition to
their being a "central" IT department. So there are separate
administrative domains (and attribute stores).
But, maybe there's a better list for me to be asking this question on?
That said, the two most recent examples of apps owners needing guidance
are apps that will be InCommon SPs.
I can use my experience with these folks to write my own "from scratch"
guidance but that seems wasteful given that there is so much expertise and
experience out there.
**
> Of course there is some
overlap, and so you might find some of the InCommon wiki pages useful
as reference material, but you'll pretty much end up having to write
your own set of "recommended practices" depending on any number of
things, including your particular IdP deployment, your attribute
release policy (both local and federation-facing), and so forth.
>
It's a good point AND many app owners need to think about "who should get
access" and "what actually needs protection and why" and "what is the
account model" before reading "do's" and "don'ts" (e.g. "Don't use names
or email addresses as internal account identifiers.))
>In any case, I'll wait for Scott to provide his favorite set of
pointers, and then I'll add a few of my own.
>
Thank you for being willing to contribute!
My best,
Marlena
More information about the users
mailing list