Docusign SSO

Peter Schober peter.schober at univie.ac.at
Mon Nov 28 21:36:50 EST 2016


* Klingenstein, Nate <nklingenstein at calstate.edu> [2016-11-29 03:00]:
> If I could change one thing in the world, "IdP URL" would mean
> "entityID" and metadata would be hosted there.  Modern versions of
> Shibboleth by convention host metadata at /idp/shibboleth, but it's
> far from consistent, which makes it far from usable in existing
> large-scale use.

Asking the entity about itself (i.e., provide some text file over the
Internet with crypographic keys etc.) also provides zero trust, making
this approach rather pointless -- unless you have solved the problem
of entity owners hosting their own metadata /signed/ by a trusted
third party.
So I wouldn't put any emphasis on pointing anyone or anything to the
IDP to get it's metadata. You might as well forget it exists (or
even prevent access to it.)
-peter


More information about the users mailing list