LocalDynamicMetadataProvider at the SP

Cantor, Scott cantor.2 at osu.edu
Thu Aug 8 08:32:43 EDT 2019


On 8/8/19, 3:25 AM, "users on behalf of Martin Haase" <users-bounces at shibboleth.net on behalf of Martin.Haase at DAASI.de> wrote:

> So we are in an unsolicited world then? Or how is the AuthnRequest created?

The metadata is looked up at first need, it doesn't matter what the need is. Discovery is not about knowing where to send an AuthnRequest now, but whose metadata to lookup to find that out. That was one of the more intelligent decisions I made early on when we implemented the SAML 2 support (the list of non-intelligent ones is a bit longer unfortunately).

Most people don't do discovery the way (some of us) do because there are few SPs that actually support every IdP in a trust fabric.

The point of LocalDynamic and the regular Dynamic plugins is to solve the problems that can be solved in the more obviously rational ways, and leave the other problems to the side.

-- Scott




More information about the users mailing list