IdPv3 - Combining HTTP resources with local files for filter, relying party , etc.
Michael A Grady
mgrady at unicon.net
Tue Oct 20 21:54:10 EDT 2015
When one configures in multiple filter files, or relying party files, etc., including ones brought in from HTTP, I assume each distinct file needs to be schema-compliant, correct? So each filter file would need the containing :AttributeFilterPolicyGroup element. But what is the minimum necessary in a relying party resource? I.e if I just want to be able add some RelyingPartyOverrides from a remote source, would that relying party file just need:
- the containing <beans ..> element
- the containing <util:list id="shibboleth.RelyingPartyOverrides"> element
- the various overrides
So can one leave out the UnverifiedRelyingParty, DefaultRelyingParty, etc. config, just having that in one of the relying party resources?
I assume if want wants to use any "tempate beans", those would also need to be defined within that same <beans> container?
Of course, the other way to handle this is through using metadata tagging and grouping to fit within custom relying party config.
--
Michael A. Grady
IAM Architect, Unicon, Inc.
More information about the users
mailing list