IdPv3 - Combining HTTP resources with local files for filter, relying party , etc.

Michael A Grady mgrady at unicon.net
Tue Oct 20 21:54:10 EDT 2015


When one configures in multiple filter files, or relying party files, etc., including ones brought in from HTTP, I assume each distinct file needs to be schema-compliant, correct? So each filter file would need the containing :AttributeFilterPolicyGroup element. But what is the minimum necessary in a relying party resource? I.e if I just want to be able add some RelyingPartyOverrides from a remote source, would that relying party file just need:

 - the containing <beans ..> element
 - the containing <util:list id="shibboleth.RelyingPartyOverrides"> element
 - the  various overrides

So can one leave out the UnverifiedRelyingParty,  DefaultRelyingParty, etc. config, just having that in one of the relying party resources?

I assume if want wants to use any "tempate beans", those would also need to be defined within that same <beans> container? 

Of course, the other way to handle this is through using metadata tagging and grouping to fit within custom relying party config.
 
--
Michael A. Grady
IAM Architect, Unicon, Inc.



More information about the users mailing list