CAS / attribute filtering
Cantor, Scott
cantor.2 at osu.edu
Fri Jun 9 19:10:19 EDT 2017
Please don't hijack old threads, it messes with the archive.
> Is this all we have to do? (Other *.my-u.edu CAS clients should not have access to campusID.)
I believe that's essentially true, but in CAS the "identity" of the system is just the location, and there's no authentication (here, and certainly generally) of the request for the data.
SAML encrypts the data over the front channel as long as there's a key and authenticates the back channel with a key, so the idea of "controlling release" has a cryptographic basis. We consider that a significant difference. Needless to say, the world largely disagrees if OIDC is any evidence.
-- Scott
More information about the users
mailing list