Burden of Authorization

David Gersic dgersic at niu.edu
Fri Dec 19 11:51:29 EST 2014


I agree with your point entirely, Scott. As you say, the powers that be want to punt half (or less) of the problem to somebody else, spend the "saved" money elsewhere, and call it good enough. While I'd argue that this is a bad idea, in the end I see it as the responsibility of the powers that be to deal with, not the IdP. So, if the powers that be have taken the responsibility for protecting the data, and have then failed to do so, I don't see that as the IdP's problem to solve.

The IdP may be part of the solution. If there's attribute release policies that would help with authorization decisions, then absolutely the IdP can help there. But it's just plain wrong to try to force the IdP to do the SP's job.

Ideally, this discussion comes up before the SP fails to do its job. In the real world, yeah, not so much.

________________________________________
From: users-bounces at shibboleth.net <users-bounces at shibboleth.net> on behalf of Cantor, Scott <cantor.2 at osu.edu>
Sent: Friday, December 19, 2014 9:25 AM
To: Shib Users
Subject: Re: Burden of Authorization

On 12/19/14, 3:12 PM, "David Gersic" <dgersic at niu.edu> wrote:

>If the SP owner doesn't care about authorization to the point of actually
>doing it, then as the IdP owner, why do _I_ care about authorization any
>more than they do? If the SP owner is silly enough to accept the idea
>that any authenticated user is authorized to use their service,then I see
>no reason to do anything beyond basic authentication and calling it good
>enough.

The main reason you'd care is if/when the resources are your university's
responsibility to protect, which is the common scenario in cloud services
today. We're taking something that could be done by us on campus and
punting it to somebody else. If it was done on campus, we'd probably think
we had to do something about this.

The problem I see is that instead of punting the whole problem, people are
buying services that solve half of it or less, and leaving the rest
unsolved, or leaving the burden of solving the rest on us while they take
any budget that existed for solving it and throw it at the vendor.

But if the resources aren't ours (e.g. the library case)? Heck yes, I
completely agree with you.

-- Scott

--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list