testing errors

Cantor, Scott cantor.2 at osu.edu
Wed Jan 17 14:05:14 EST 2018


On 1/17/18, 1:21 PM, "users on behalf of Tom Scavo" <users-bounces at shibboleth.net on behalf of trscavo at gmail.com> wrote:

> If there were a Java SP component, I think you could argue that point
> successfully, but without that, I don’t think that’s a reasonable
> expectation. The combined deployment footprint for the IdP + SP is
> substantial.

I think it is both reasonable and unavoidable, but I also didn't say that anybody had to necessarily run *this* software on both ends. I'm saying you run *something* for appropriate testing and insight.

> We entered the long tail of SAML software deployment a long time ago.
> Basically what I hear you saying is that small IT shops (which is all
> that remains on the IdP side) should rely on a hosted solution (which
> may or may not be based on the Shibboleth software). I guess that’s
> okay but it would be better if the project just came out and said that
> if in fact that’s the goal.

It isn't anything we're taking a position on but running a "simpler" version of either end doesn't change the fact that you can't do it properly if you don't run both ends for basic operational insight and testing.
 
> The TestShib SP might expose endpoints to test various levels of
> attribute release, thereby reinforcing the prevailing party line with
> respect to attribute release. It could also expose endpoints that
> tested IsPassive, ForceAuthn, and RequestedAuthnContext.

It could do a lot of things, but if our members don't ask us to spend their money to do it, we aren't going to do it. It's that simple, and has been the consistent position of the project for a very long time. We will do what they prioritize us to do, and if asked, we'll assess what we have to stop doing in order to add this. Or decide we have the excess funds to bring in a resource to do it if that's what people decide is worth doing.

> All of this is my own opinion of course: If you downgrade TestShib, or
> scare people away by heaping guilt upon them, you’ll end up shooting
> yourself in the foot.

I'm not guilting anybody. If you want to run a SSO system with any hope of success, you run both ends. You will not do an effective job if you do not. The sites that operate unreliable IdPs inevitably are the ones that don't run SPs and vice versa. That has been true for the life of the project. It is a fact. I see it often enough with the companies I have to integrate with; their SP breaks and they literally throw up their hands because they have no operational view into the system due to the fact that they only run half a system.

What has gone "wrong" is that federation gave people the misguided idea that because it tends to be something people might only really care about one half of that they somehow can avoid the need to run both halves, but they cannot. SSO is inherently a two part process.
 
-- Scott




More information about the users mailing list