Issues NonParticipant using Federation Metadata?
Wessel, Keith
kwessel at illinois.edu
Thu Nov 2 14:30:34 EDT 2017
It should work, and that’s certainly not the only vendor doing that. I agree that it’s rather silly; they take the time to consume InCommon metadata, but they don’t bother to join InCommon. It may not make a lot of sense, but there’s nothing technically wrong with it other than the obvious pitfalls of not publishing metadata with the federation. At least they’re gaining the benefits of consuming IdP metadata from the aggregate.
Keith
From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Dan Malone
Sent: Thursday, November 02, 2017 1:26 PM
To: Shib Users <users at shibboleth.net>
Subject: Issues NonParticipant using Federation Metadata?
I'm sure there are some non-technical issues we can come up with here, and I have already offered my standard "...join InCommon ... it's good for all of us ... we will sponsor you..." plugs to them.
My question to this list is: Are there any technical issues with this scenario?
From this vendors documentation:
IRBManager automatically accepts IdPs published in the InCommon Federation’s metadata list, and we can add other metadata sources upon request. Our security metadata XML is available at https://shibboleth.irbmanager.com/metadata.xml.
On the SP side, the SP is consuming InCommon metadata and therefore can get our IDPs metadata given our entityID.
On the IDP side, I consume their SP metadata directly (not via InCommon) and the SP entityID.
Not all configured yet, but this seems like it should work.
Am I missing anything?
Thanks,
Dan
--
Dan Malone
Lead Identity Management Architect
Information Technology Services
California Polytechnic State University
San Luis Obispo, California
Direct 805-756-6326
dmalone at calpoly.edu
More information about the users
mailing list