Development Test Environment

Cantor, Scott cantor.2 at osu.edu
Fri Mar 20 11:31:17 EDT 2015


On 3/20/15, 11:18 AM, "Michael Dahlberg" <olgamirth at gmail.com> wrote:

>While I don't mind including the ~10 new sets of metadata into our shib IdP installation, I can't help but think there is a better way of giving them a realistic view of the site that they are developing with regards to the authentication and authorization process.

Depends on the various knobs involved, but with a push scenario and encryption off, you can impersonate any registered SP just with local /etc/hosts modifications.

Alternatively, what I tend to tell people is that for basic integration with the SP where the only touchpoints are the attributes consumed, the whole point is that you don't need the SP to produce the same outcome in the application. It's portable. You can spoof headers, manipulate the web server config, etc. to produce exactly the same interface to the application, and manipulate the data arbitrarily. That's the advantage.

-- Scott



More information about the users mailing list