on-prem application

Cantor, Scott cantor.2 at osu.edu
Wed Mar 20 21:18:14 EDT 2019


On 3/20/19, 6:39 PM, "users on behalf of Lohr, Donald" <users-bounces at shibboleth.net on behalf of lohrda at jmu.edu> wrote:

> If a on-prem (local hosted) application (which points to our only IdP) 
> is developed, installed and mostly managed by the vendor, there is 
> advantage in having it's metadata joined with InCommon's metadata.

The issue is who's doing it. You registering somebody else's metadata is pointless. And when you try to get them to join a federation, the answer's probably going to be "no" unless you have very strong policy behind that. So there's a good chance you won't have a choice anyway.

> At this point I do not understand the "key change" reference.

I'm in the process of changing my IdP's signing key, and dealing with all of the different cases within InCommon and on-campus across 1000+ services. That's the whole point of all of it.
 
-- Scott




More information about the users mailing list