simpleSSO
Klingenstein, Nate
nklingenstein at calstate.edu
Wed Dec 21 22:08:40 EST 2016
The contents of the certificate become very relevant, but no longer overlapping nor vague.
And, particularly, to maintain referential integrity, does:
A) Metadata point to a certificate, as in SAML
B) A certificate point to metadata, as I don't know has been done before
C) Both?
I think my answer is B. The providerId has to be put in the certificate. For the application, that's the primary identifier. For the IdP, it's informational, while the hostname is the primary identifier, again to make application implementation braindead.
Sorry for using the list for this, but I hope it helps you think about pressing deployment problems from a new angle. Shibboleth as software is protocol-agnostic and a reasonable framework for implementation since it has most of the crucial machinery built already.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20161222/1ba069c8/attachment-0001.html>
More information about the users
mailing list