Shibboleth installation clarification
Cantor, Scott
cantor.2 at osu.edu
Wed Feb 1 12:25:47 EST 2017
On 2/1/17, 11:29 AM, "users on behalf of Klein, Stephen" <users-bounces at shibboleth.net on behalf of SKlein at gc.cuny.edu> wrote:
> We are setting up Shibboleth, again as an Identity Provider, for HatthiTrust authentication, so not sure how to approach
> this task. Can someone send me a sample?
> I also see:
> ‘load SAML metadata for the service provider with which you will interact’
The IdP defaults to responding to requests with services only for which SAML metadata is supplied, and to make the rules one creates for attribute release actually mean something. Sources of metadata are a local decision, the general documentation can't tell you how to do it because it doesn't know who you are, what your deployment needs are, etc.
If you're trying to federate with InCommon participant services that are registering their metadata with the federation and don't have out of band management approaches (HathiTrust being an example), then you bootstrap trust in the InCommon metadata by verifying the signing key and then install the necessary configuration for that metadata source, with the appropriate verification checks. InCommon provides its own documentation on that with the advisable settings. After that it's automatic.
-- Scott
More information about the users
mailing list