Central discovery service filter by role?
Peter Schober
peter.schober at univie.ac.at
Thu Jun 26 11:31:22 EDT 2014
* Tom Poage <tfpoage at ucdavis.edu> [2014-06-26 17:21]:
> Certainly, the embedded discovery service is one option, except that
> we end up redoing the same work over and over for each new SP stood
> up, not to mention maintenance burden/cost for any change to the
> discovery component.
The EDS can be deployed anywhere you can run a Shib SP (which doesn't
need to protect anything) and function as a "generic" SAMLDS, not
visually/visibly integrated with any specific SAML SP.
E.g. if you try to log in to the Shib Wiki or the Shib issue tracker
(two seperate SAML SPs) both will refer you to
https://shibboleth.net/shibboleth-ds/
The fact that they all share a DNS domain is immaterial here and
doesn't really help illustrate my point all that much, but you can
deploy the EDS (with a Shib SP) also as a "central" DS if you wanted.
-peter
More information about the users
mailing list