SP Requiring/Requesting MFA (was Re: Customizing Second Factor Configuration in mfa-authn-config.xml)
Cantor, Scott
cantor.2 at osu.edu
Fri May 14 21:19:50 UTC 2021
On 5/14/21, 5:13 PM, "users on behalf of Ullfig, Roberto Alfredo" <users-bounces at shibboleth.net on behalf of rullfig at uic.edu> wrote:
> OK, but since we don't manage many SPs, metadata-driven configuration doesn't seem very useful.
You can apply attribute tags with metadata filtering; where the metadata comes from isn't a limiting factor.
The only subtlety is the concern that any tag you honor could come in from the metadata source itself, which is why the filter for tagging allows a condition script that can strip pre-existing tags as well.
But InCommon isn't really a source one needs to be that worried about, at least right now, as they don't allow tags to be fed in other than very specific ones they allow to be published.
The documentation explains why using overrides is a dead end. You end up with a combinatorial explosion of them in the end. Other than that, there's not a huge difference between overrides and tagging through filtering.
Another difference is that the Unicon GUI supports applying settings with metadata, for those who are into GUIs.
And still another consideration is just consistency. The vast majority of metadata in virtually any deployment is not from outsides sources. If you really manage *no* metadata, you are in a very small minority and you're going to see that change eventually.
-- Scott
More information about the users
mailing list