IDPV3 InCommon and EDUCAUSE examples?

Cantor, Scott cantor.2 at osu.edu
Thu Jul 14 17:06:02 EDT 2016


> I was looking for a cut and paste set of examples (This goes in metadata.xml,
> this goes in relying-parties.xml, etc)

The only real cut and paste is the metadata and that's just InCommon's, and it provides that example on its web site for supported software, including Shibboleth, see [1].

All of the attribute material is local ultimately but the examples in the software are about as much as anybody can just hand you. The approach to release policy is local (using R&S essentially makes it moot, as does a default release policy). If you want to just brute force a simple policy releasing some explicit list of attributes, the software comes with basic examples that show it doing that.

There is nothing in relying-party.xml unless you have to make non-defaulted choices that are not all that common, with the exception of supplying a NameID Format to use if you can't drive it with metadata. This SP doesn't need a custom NameID, so that case doesn't apply, and so you put nothing in relying-party.xml.

If you're touching that file a lot, let alone every SP you deal with, something is definitely wrong. You don't need to do that. Even NameID format selection is better handled with metadata. The other setting that helps make it rare to touch it is the property called idp.encryption.optional, which I believe is worth turning on. But again not relevant for this SP.

-- Scott

[1] https://spaces.internet2.edu/display/InCFederation/Shibboleth+Metadata+Config



More information about the users mailing list