InCommon eduGain and release policies

Jeffrey Crawford jeffreyc at ucsc.edu
Fri Jan 29 17:51:14 EST 2016


Jeffrey E. Crawford
ITS Application Administrator (IdM)
831-459-4365
jeffreyc at ucsc.edu

Both pilots and IT professionals require training and currency before
charging into clouds!
---------------------------------------

On Fri, Jan 29, 2016 at 1:54 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:

> > ​So something like eduGain = (!registerd-by-incommon) | (​
> > !local:metadata:group)
>
> Basically. I guess I was thinking more like you just make that the default
> behavior and don't really need to call it out. It's the others you'd
> override.
>

​Okay so if in the relying-party.xml file you specify the
​nameIDFormatPrecedence, that doesn't apply by default to the override if
it is omitted (meaning the override goes back to the default precedence, if
nameIDFormatPrecedence is not in the override section definition.

>
> > Since going to v3 I've been collecting them into a single metadata file,
> but not
> > all of them yet. Is using urn:mace:incommon really that big of a problem?
> > Seems more "exact" to me.
>
> It's fine until it totally breaks I guess. Point is, "registered by
> InCommon" is the exact rule you're looking for if that's what you're trying
> to apply a rule to. "Contained in InCommon group" doesn't really mean
> anything once eduGain hits (I don't think?), and won't work at all outside
> of the aggregate.
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160129/d2f4db00/attachment.html>


More information about the users mailing list