LocalDynamicMetadataProvider at the SP

Nate Klingenstein ndk at signet.id
Thu Aug 8 03:42:37 EDT 2019


Martin,

> > Lookup of the IdP once the assertion comes back.
> 
> So we are in an unsolicited world then? Or how is the AuthnRequest created?

In a sense we are in both an unsolicited and bilateral world, hence the LocalDynamic provider.  It's probably better in Europe where the federations are stronger and academia tends to be more self-contained.  But for example, with Office 365, it's by domain/tenant.  With SAMLtest, it's by typing in your entityID(which is then hashed and looked up with the LocalDynamicMetadataProvider).

I argued back in the very early days of Shibboleth that metadata should be referenced by special DNS records(like MX).  That one got shot down very quickly by the actual practitioners who had to deal with their DNS administrators and actual applications -- I was still just taking notes -- but I still see advantages to the solution.

Take care,
Nate.


More information about the users mailing list