Default NameIDFormat Metadata Elements

Cantor, Scott cantor.2 at osu.edu
Thu Sep 15 10:12:57 EDT 2016


> Which way? I'd assume that an nnnService would require an associated
> protocol but not vice versa.

That's correct. The protocol has to be there if you want to ensure that the endpoint is seen, but if you set the protocol but provide no endpoints, that should just be irrelevant. Not something to do on purpose but it doesn't hurt anything, just changes the error messages you'll see.

> Actually, AFAICS, the spec is stronger than that - it infers that any SAML2
> support by the _ENTITY_ requires that in the
> protocolSupportString, not limited to the RoleDescriptor element.

Well, it's a role-level attribute, so there's no real concept of entity-level support. I'm sure the terminology is sloppy in some places.

-- Scott



More information about the users mailing list