how would we suggest improving the user experience at this SP
Steven Carmody
steven_carmody at brown.edu
Wed Jun 4 10:57:10 EDT 2014
Hi,
I've been trying to use a Shib-enabled SP, and I've been having some
problems. I'm wondering if this group might provide some "best practice"
info addressing some of the issues that I encountered. I'd prefer to not
identify the site. Rather, I think the problems I encountered may be
evident on lots of sites, and are more general than just this one site.
I went to the public front page, and clicked a button. This transferred
me to a variation of the Discovery Service implementation provided by
the Shib project. I selected my campus, and was transferred to my IDP.
(Note -- my login page did display the Description text for this SP;
however, the logo url in the metadata element for this SP was stale.)
I was then presented with an error page:
> There seems to be a problem with your account.
> We have not received your email address from your identity provider
(IdP). This might be because your home organization IdP is not releasing
your email address.
> Please see your home organization's IdP administrator. See our
Attribute Release Policy for more information.
I'd like to identify some of the issues I encountered, and see if there
are suggestions:
1) This site is a member of InCommon, and is clearly supporting Higher
Ed Identity issues, but for unknown reasons this is NOT an R&S site. If
it were, my IDP would have released the desired attributes.
2) This seems to be a "big" SP hosting many services, which may explain
why no R&S. I'm told that all of the services require the same
attributes, tho. What might prevent this site from being tagged as R&S ?
3) There was no indication up front during the Login process that
attributes are requested or required. Where should that have been done ?
4) There was no indication of the SP's entityID value. My IDP admin
needs that value in order to construct an Attribute Release Filter.
5) The site did not follow InCommon's recommended error handling
recommendations:
https://spaces.internet2.edu/display/InCFederation/Federated+Error+Handling
Instead, I was presented with this page containing this text:
We have not received your email address from your identity provider
(IdP). This might be because your home organization IdP is not releasing
your email address.
Interestingly, this text does not agree with the RequestedAttribute
elements in the metadata entry.
6) That error page contains a dead link to attribute policy.
We're sorry. It appears that something has broken on our system.
Don't worry, the web support team has been notified and will fix this
issue as soon as possible.
7) If I retry the whole process, I am immediately redirected to the main
web page for the site. No Discovery Service, no IDP. I understand that.
But, instead of seeing an error, I'm redirected to a useless url.
What should it do ?
thanks for any and all suggestions !
More information about the users
mailing list