minimal/no backchannel shibboleth idp configuration
Eric Goodman
Eric.Goodman at ucop.edu
Wed Dec 17 13:38:52 EST 2014
> >- An IdP should avoid SAML2 attribute query altogether. (I've never
> >known an IdP deployment that actually needed a SAML2 AttributeService
> >endpoint in metadata.)
>
> VOs use them quite a bit.
I almost made the same response. I suspect the point in the parentheticals is still valid: the VO's IdP can support attribute query for its own "internal" SPs, but may not advertise it in metadata.
So I'd perhaps suggest rephrasing Tom's comment to be "an IdP should avoid advertising SAML2 attribute queries in federation metadata". I think saying IdPs should avoid it altogether is perhaps overly strong. I agree it's probably generally unlikely that an IdP supports general attribute-query access.
--- Eric
More information about the users
mailing list