SAML1.1 attribute release on Shib 3
Morris, Andi
amorris at cardiffmet.ac.uk
Wed Feb 15 12:49:41 EST 2017
Hi Scott,
We're not intending to push any personally identifiable information via this method, just the targetedID and the scoped affiliation attributes. Is this still risky?
Should I pull the attribute query out of the metadata if I'm pushing the attributes? If I push, does this still go through the backchannel connection?
Cheers,
Andi
-----Original Message-----
From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor, Scott
Sent: 15 February 2017 17:41
To: Shib Users <users at shibboleth.net>
Subject: Re: SAML1.1 attribute release on Shib 3
On 2/15/17, 12:32 PM, "users on behalf of Morris, Andi" <users-bounces at shibboleth.net on behalf of amorris at cardiffmet.ac.uk> wrote:
> Thanks everyone! Rod nailed it with the attribute push. Adding the
> following line to my default relyingparty.xml file has released the attributes over SAML1.1.
Well, you don't do this *and* support queries, and you really need to decide if you want to do that if you're pushing private data. Pair-wise IDs are meant to be private data. I would not personally be very comfortable doing that.
-- Scott
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
________________________________
[Cardiff Metropolitan University - Queens Anniversary Prizes 2015]<http://www.cardiffmet.ac.uk/news/Pages/Cardiff-Met-research-recognised-in-Queens-Anniversary-Prizes-for-Higher-and-Further-Education.aspx>
More information about the users
mailing list