saml proxying scoped attributes...best practice
Bobby Lawrence
robertl at jlab.org
Wed Nov 13 14:28:39 UTC 2024
> Absurdly large metadata ended with MDQ. There really is no "special" configuration for mutliple IdPs in Shibboleth.
The MDQ is great for IdPs to fetch metadata for SPs on the fly, but the reverse isn't ideal. SPs need to know all IdP metadata up front in order to provide discovery and the MDQ doesn't really work for that. The result is that if an SP is to accept logins from any federated IdP, it needs to load a large metadata file. Luckily InCommon (and maybe others) provide an IdP-only variant, but its still huge.
More information about the users
mailing list