Discovery by Email, Domain, or entityID

Nate Klingenstein ndk at signet.id
Thu Aug 8 13:35:21 EDT 2019


Scott,

> There is <mdui:DomainHint> :
> 
> https://docs.oasis-open.org/security/saml/Post2.0/sstc-saml-metadata-ui/v1.0/cos01/sstc-saml-metadata-ui-v1.0-cos01.html#_Toc15657212

Thank you, I was unaware of that field.  It's as promising as anything we've got today.  I have several concerns about it, though:

1)  I wish it were in the main md namespace since this is useful for domain lookups for many purposes, not just discovery or UI's.  Also, mdui is not particularly widely deployed by commercial services.
2)  DomainHint has some ways to go in terms of support even within eduGAIN, though as you note we're off to a good start.  But, I feel the world is running around building its own solutions, and once those are in place, they're hard to displace.
3)  We're still starting at the metadata and ending up at the domain, which still means we need to know the location of the metadata first.  Subject to all of Peter's caveats, I still prefer a DNS-first approach, since we already have the domain in hand.

Starting at the metadata does confer the advantage of co-existence with other discovery mechanisms, definitely.  But, I view that as something of a neutral factor or even disadvantage here if consistency or simplicity are the principal goals.

If flexibility and the preservation of privacy are the principal goals, then there's a greater advantage due to the flexibility.

There's no reason the two approaches can't exist in parallel, but that's the world we're living in today, and we don't seem to like it.  The community would have to dedicate itself pretty hard to "something" in order to nudge the broader deployment needle.  We're almost at 10000 entities on SAMLtest, and only 784 of them contain the string "mdui".

Best wishes,
Nate.


More information about the users mailing list