simpleSSO
Klingenstein, Nate
nklingenstein at calstate.edu
Thu Dec 22 10:02:24 EST 2016
Today, SAML metadata points at certificates in various ways through X509<blah> elements. I want the link in the other direction. I don't know why yet, but it feels completely right. I have to think to get why.
I think it's who versus what, again. Who I am is a fairly persistent or permanent thing. "What" I say changes all the time, such as my GUI info or the endpoints I'll be using.
"Who" can't change often, just in terms of human capacity, making a more permanent token for that purpose and that purpose alone interesting. Once I have someone to sue, things become much less serious, and I can start thinking about the "what", so the flexibility that simpleSSO gives is defensible.
Since "who" shouldn't change often and it must be matched, that's where I want my pointer to live. That's the "glue point". So, put the pointer to metadata in the certificate.
SAML metadata alone kinda already has this problem without the distinction, now that you mention it. Consider how hard it is to change your entityID. Consider how easy it is to change anything else.
simpleSSO uses certificates to say "who", leaving it hard to change your "who" and easy to change anything else. This gives strict assignment of authority, but a way to check "what" with multiple attesters, including your counterparty if you so choose.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20161222/8d11f0e1/attachment-0001.html>
More information about the users
mailing list