[EXTERNAL] Re: unable to capture eppn information from SAML2/POST at SP

Peter Schober peter.schober at univie.ac.at
Tue Jun 12 10:07:11 EDT 2018


* O'Quinn, Dennis <DENNIS_OQUINN at homedepot.com> [2018-06-12 15:22]:
> I know that information is there collectively, but, if you have zero
> exposure to this stuff, then it's a little hard to piece it all
> together.

I found this to be quite helpful:
https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPGettingStarted
but if you're being thrown in at the deep end, having to deal with
IDPs that have no clue whatsoever (meaning you as the SP have to work
around all kinds of weird, not recommended, nonsensical and/or
outright wrong/illegal bahaviour) no amount of properly chosen
software defaults will save you from learning how to configure/use the
software.

It's the refusal of most commercial entities in this space (from
home-grown SP software to "cloud" IDPs) to stick to sane, properly
chosen defaults and behaviour that doesn't bend the spec until it's
unrecognizsable), that causes work for everyone else.

The sad part is that those learning about the tech in these
environments have no idea that there would even be better ways of
doing things (were stuff "just works"), because all they've ever
seen/known is manual, bilateral, arbitrary twisting and turning of
their respective software "until it works" (or copying the worst
offenders because they're popular due to other factors), without any
regard to how it's intended to be used.

(Sending a local userid as a transient NameID -- anytime. "No we don't
support attributes, you must send this weird crap in this weird place,
we don't look elsewhere" -- sure! "We don't even look at NameID
formats, that's what all the cloud vendors are doing, too, our
customer want it this way" -- any day. etc.pp.)

> Also, I get the distinct impression from some of the group members
> that there is a pretty high expectation (or assumption?) of
> fore-knowledge on behalf of the users asking questions.

There's no way anyone could negate a sentence about the impressions
someone else may get or not, but it doesn't match my personal views:
Cross-organisational single sign-on is a highly technical field, so at
the very least the same required skill set should be employed as for
any other similarly involved technical topic. (Esp one also involving
distributed computing, large-scale deployments, cryptography, identity
management, etc.)

What's non-optional for a good experience is the ability to ask
technical questions and trying to understand the answers others have
taken their time to provide -- including asking some more if the
answers themselfs are unclear, as will often be the case in highly
technical communities.
(It may also be a dying skill, not sure.)

> I think you guys may want to consider bumping your responses up to
> the really complex stuff and letting others in the group handle the
> little stuff...  That may reduce your load quite a bit...

Being one of those "others" I have some 4000+ posts in this list's
archives that say "I'm trying!" as good as I can.

Though I don't agree with the implication that answers from highly
qualified people (e.g. Scott) will *necessarily* provide for a worse
experience for newcomers.  Conversely I doubt that more answers from
people who only understand small parts of any given problem scenario
will *necessarily* improve it. That latter still hasn't stopped me
from trying.

-peter


More information about the users mailing list