Evolving Attribute Release Policies for campuses

Cantor, Scott cantor.2 at osu.edu
Tue Apr 5 19:59:32 EDT 2016

On 4/5/16, 7:47 PM, "users on behalf of Peter Schober" <users-bounces at shibboleth.net on behalf of peter.schober at univie.ac.at> wrote:

>(But recent discussions have shown that some even consider only
>sending ePTID to be sufficient for an IDP's claim to R&S support...)

That's the part that just isn't right, so that really does bug me. The text is 100% clear that the "minimal" subset of the bundle is NOT just that one attribute. The wiggle room is around *who* you might release the full subset for, but if it's not a substantial population, there just isn't any leg to stand on here. If that's becoming any kind of widespread view, we should work in REFEDS to stamp it out and soon.

I just wish the category had not required that SPs include requested attributes in metadata. I don't remember why we did that and it was a mistake. We'd be in relatively fine shape if the spec actually precluded it. The work of making that useful should have landed on something other than R&S.

-- Scott

More information about the users mailing list