[EXTERNAL] Re: unable to capture eppn information from SAML2/POST at SP

Cantor, Scott cantor.2 at osu.edu
Tue Jun 12 09:52:20 EDT 2018


> Well, that wasn't a complaint or attack....

No, I didn't think it was.
 
> What I was really missing (and it is probably out there where I just haven't
> found it yet) was some sort of primer that tied at least the 3 (or more?) files
> together a little better...  Like the shibboleth2.xml (and metadata) vs. attribute-
> map vs. attribute-policy vs. ???...

Yes, that's a major gap (though the V3 docs I think will be a bit tighter in that respect), and there isn't one because this project isn't resourced to do documentation as a core deliverable. All of that work has been best effort by the developers, mostly me, in the extremely limited time available in between doing the work that's actually been recognizably funded. As a result, the docs are largely about reference material and documenting how to do things and very little on concepts. That also stems from the fact that it's a very hard thing to write and there are roughly zero tech writers out there who understand SAML well and exactly zero willing to do any work for us. We've tried, believe me.

> Also, I get the distinct impression from some of the group members that there
> is a pretty high expectation (or assumption?) of fore-knowledge on behalf of
> the users asking questions.

Of SAML, yes. Much like with an LDAP server, the docs aren't generally there to teach anybody LDAP. But there aren't good resources anywhere on the real nuts and bolts of it and most people's exposure to it, if they have any, is via a lot of broken, sloppy, and immature practice that's fairly endemic to commecial SAML.
 
> I think you guys may want to consider bumping your responses up to the really
> complex stuff and letting others in the group handle the little stuff...  That may
> reduce your load quite a bit...

I mostly do unless it's a very quick response.

-- Scott



More information about the users mailing list