IdP attribute filter strategy
Jeffrey Crawford
jeffreyc at ucsc.edu
Thu Jun 4 20:22:09 EDT 2015
It sounds intriguing. Do you have an example of how it would be configured?
Jeffrey E. Crawford
ITS Application Administrator (IdM)
831-459-4365
jeffreyc at ucsc.edu
Both pilots and IT professionals require training and currency before
charging into clouds!
---------------------------------------
On Thu, Jun 4, 2015 at 4:46 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> On 6/4/15, 4:26 PM, "Jeffrey Crawford" <jeffreyc at ucsc.edu> wrote:
>
>
> >
> >Inspired by research and scholarship I've started using our urn:mace
> >registration and creating attributes to match rules. Basically defining a
> >filter once and applying it in the metadata we load manually. However
> >this doesn't translate real well to InCommon Metadata.
>
> I might not be fully following that, but in case you didn't know (and I
> don't know why you would, it's not really even documented much yet),
> there's a metadata filter (not an attribute filter) in the IdP that is
> modeled after one the SP supports that lets you *add* EntityAttribute tags
> to an entity's metadata on the fly.
>
> The idea being to possibly consolidate some attribute release policy
> around EntityAttribute extensions (like with R&S), but then attach your
> own tags on the fly to entities (be they yours or from InCommon) so you
> can trigger your policies.
>
> I don't know if that sounds useful to you or if it has the same drawbacks,
> but thought I'd mention it.
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20150604/7df2d94a/attachment.html>
More information about the users
mailing list