logging the outgoing SAML

Brent Putman putmanb at georgetown.edu
Thu Aug 31 17:24:13 EDT 2017



On 8/31/17 4:02 PM, Brent Putman wrote:
>
> On 8/31/17 2:45 PM, Cantor, Scott wrote:
>> On 8/31/17, 2:40 PM, "users on behalf of IAM David Bantz" <users-bounces at shibboleth.net on behalf of dabantz at alaska.edu> wrote:
>>
>>> Seems a shame to add all that encrypted data to the logs just to get the outgoing SAML for a minority of unencrypted assertions
>> Just pop in a RFE for a separate Assertion category.
> IIRC, that's the way we originally did it.  But for some reason we
> un-did it and make it just part of the regular Encrypter logging.  I
> think the discussion is in the original issue.  But we can certainly
> re-visit.

For the record it was https://issues.shibboleth.net/jira/browse/IDP-575.
Originally we had added special category SAML_PRE_ENCRYPTION.  The
reasons for removing that and just using the standard Encrypter category
aren't mentioned in the issue.  We must have discussed on the dev call
or something.  The last entry is just Tom noting that he added the
finalized Encrypter example to logback.xml.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170831/57637cf0/attachment.html>


More information about the users mailing list