Confusing integration with iGrad/Enrich vendor
Cantor, Scott
cantor.2 at osu.edu
Thu Apr 27 19:35:37 UTC 2023
> I assume we’re missing something obvious.
Well, bear in mind that some of those integrations don't rely on InCommon at all so there's no conflict at all there. The ACS thing...I am hard pressed to believe though that people just worked around that. I wouldn't bet a lot of IdPs even could, but you might also bear in mind that a lot of broken IdPs encourage IdP-initiated set ups and probably would have a way to build in rules that are based on the button you push in the portal, not just the entityID.
FWIW, I am familiar with iGrad and have integrated that, but not the second one, so I haven't hit the conflict and if I had, they would have been unhappy with my responses to their nonsense.
Management does not understand how all this works. That can be a pain, but it also means they are not remotely equipped to question me when I say "this can't be integrated, the vendor is not following the standard". And that's what I would do.
If you want to complicate your system so that whoever comes later has to deal with it and complain that Shibboleth is "too hard", then you'd have to build a scripted attribute that checks the ACS location in the request.
-- Scott
More information about the users
mailing list