IdP attribute filter strategy

Jeffrey Crawford jeffreyc at ucsc.edu
Thu Jun 4 12:26:27 EDT 2015


Greetings Everyone,

I'll try and keep this short to save everyone time.

I'm working on the Shibboleth 2.4 to 3.1 upgrade. I want to come up with a
better strategy on managing, or better said "not" managing attribute
filters.

As most institutions I'm sure, we are members of InCommon and we manage
lots of one off metadata. Currently our one off metadata is grouped into
EntityDescriptors in separate files, and we create filters based on that.
Problem is we wind up repeating a lot of rules and we have lots of files to
load. Since we are only grouping similar instances of the same service (qa,
prod, test, etc.) we are creating a group and filter per service, and I
want to find a better way.

Then we have to make "other" filters for entities in InCommon, with the
exception of research and scholarship, based on their entityID's.

Inspired by research and scholarship I've started using our urn:mace
registration and creating attributes to match rules. Basically defining a
filter once and applying it in the metadata we load manually. However this
doesn't translate real well to InCommon Metadata. I could use
"RequestedAttribute" for both InCommon and our local metadata, but
obviously we don't control the attributes listed within InCommon. However
now that v3.1 allows us to display the attributes we are about to send,
that might be okay. Therefore I wanted to ask the community about how they
manage attribute release.

I've seen the following on my search of the list. Attribute release bundles
(We tried that and it seems like everything is an exception). Release a
single filter at a time and list the entityID's per filter (Difficult to
see the entire suite of attributes)

Jeffrey

Both pilots and IT professionals require training and currency before
charging into clouds!
---------------------------------------
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20150604/070259de/attachment.html>


More information about the users mailing list