minimal/no backchannel shibboleth idp configuration
Cantor, Scott
cantor.2 at osu.edu
Tue Dec 16 16:45:08 EST 2014
On 12/16/14, 8:42 PM, "Paul B. Henson" <henson at csupomona.edu> wrote:
>
>Based on
>https://wiki.shibboleth.net/confluence/display/SHIB2/MetadataForIdP, it
>looks like the idp itself doesn't pay any attention to them and they are
>also not consumed by the shibboleth SP? However, in addition to being in
>the default install metadata, they are also in the example metadata on
>that page. Is there any particular reason to include or not include these
>entries in the metadata?
Just documentation. It's not just sofwtare that ever looks at metadata.
But if it's not accurate, it isn't useful. If you support other kinds of
identifiers depending on policy, then listing only those isn't useful to
anybody.
>If trying to deploy a minimal shib idp, is there any particular reason to
>include or not include this binding?
There isn't much use of it, but if POST and Signed Redirects work,
SimpleSign will, so it doesn't matter that much, it's no risk certainly.
>Also, if you do not plan to support SAML1 and do not advertise it in
>metadata, would it be a best practice to also remove the ProfileHandler
>configuration in handler.xml?
Probably.
> And all of the SAML1String AttributeEncoder configuration in
>attribute-resolver.xml?
If you'll never use them, sure.
> Or the SAML1 configuration in internal.xml?
Doubtful.
-- Scott
More information about the users
mailing list