unable to capture eppn information from SAML2/POST at SP
Cantor, Scott
cantor.2 at osu.edu
Mon Jun 11 18:35:23 EDT 2018
On 6/11/18, 6:29 PM, "users on behalf of Cantor, Scott" <users-bounces at shibboleth.net on behalf of cantor.2 at osu.edu> wrote:
> BTW, Much of the documentation I am reading out there seems to imply that the configuration is being done by 'one'
> entity with access to "both" IdP and SP configurations and logs simultaneously.
What I said notwithstanding, certainly it is true that it's impossible to test and operate an SP effectively without an IdP, and if you don't control *an* IdP, you will pay for it. That doesn't imply you control every IdP you work with, but if you try and run an SP without one, you'll fail in various ways eventually simply due to lack of robust testing. SSO systems have two halves and you either run both or you eventually pay for it in reliability. You can't wish that need away.
(The best choice of a simple one-off IdP is not something I can really answer. I doubt a Shibboleth IdP is a good choice for most as it's more than one would need, but I don't have to answer that question since my primary OSU role is running one, so my gap these days is the opposite, having control over SPs to test with.)
-- Scott
More information about the users
mailing list