ServiceNow Multi-Provider SSO integration follow-up
Paul B. Henson
henson at csupomona.edu
Fri Jul 11 23:33:59 EDT 2014
On Thu, Jul 10, 2014 at 06:17:30PM -0700, Cantor, Scott wrote:
> I'd be a little leery of that if it's undocumented. Sending a NameID isn't
> *that* hard.
Eh, it's not "undocumented found a secret configuration value in the
source code and used it", it's more "undocumented it's an option that
can be set but there's no clear explanation of it or how to use it or
what it does". Once what it does has been empirically determined, I
don't think it's very likely it all happened by accident and it's
suddenly going to disappear. It seems most likely somebody with a clue
improved their previous implementation while working on the multi-sso
module, but didn't really describe it very well, or coordinate with the
documentation team about actually telling people how it worked.
Sure, it's not hard; in fact, I initially set it up that way and it was
working once the consultant turned off attribute support. I had to go
out of my way to undo it and configure it to just use a normal
attribute. But it was worth it, as it's a lot cleaner, and ended up only
needed a kludge in the relying party config instead of in three separate
config files. I hate kludges.
--
Paul B. Henson | (909) 979-6361 | http://www.csupomona.edu/~henson/
Operating Systems and Network Analyst | henson at csupomona.edu
California State Polytechnic University | Pomona CA 91768
More information about the users
mailing list