Recommended Next steps...?
o haya
ohaya1001 at gmail.com
Tue Mar 25 16:12:23 UTC 2025
Hi,
Ahh, apologies. "XASP" (X.509 Attribute Sharing Profile) is an OASIS
profile for attribute sharing using SAML 2 (
https://docs.oasis-open.org/security/saml/Post2.0/sstc-saml-x509-authn-attrib-profile-cd.html).
Basically, the "SP" or "Attribute Requester" end sends a request with a
user's certificate information to the "IdP" or "Attribute Authority" or
"AA" and the AA returns a message to the SP/AR with the requested
attributes.
I should have explained that and specifically ask if Shibboleth (both the
SP side and the IdP side) supports that?
Jim
<https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=webmail>
Virus-free.www.avast.com
<https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=webmail>
<#DAB4FAD8-2DD7-40BB-A1B8-4E2AA1F9FDF2>
On Tue, Mar 25, 2025 at 11:20 AM Peter Schober via users <
users at shibboleth.net> wrote:
> o haya via users <users at shibboleth.net> [2025-03-25 16:08 CET]:
> > Two of the things that I want to be able to test are to (a)
> > implement/prototype attribute sharing (XASP) using Shibboleth, and (b)
> > after that, similarly implement/prototype identity federation (again,
> using
> > Shibboleth).
>
> FWIW, I never heard of "XASP" and I don't know what specifically you
> mean by "attribute sharing". And of course different people/projects
> mean different things when they say "identity federation".
>
> > Looking at the docs, I think that I need to stand up an LDAP (OpenLDAP)
> > server as the backend for the IdP/Attribute Authority/AA), and integrate
> > that backend with the IdP that i just recently stood up.
>
> Note that the IDP can also pull data (about people, usually) from an
> RDBMS or via HTTP-based APIs. LDAP is fine if you're comfortable with
> it (hardly anyone is, these days, IMO) or have the tooling so you
> don't have to care about it (i.e., container images).
>
> > I think that I am also going to need to stand up a Service
> > Provider/Attribute Requester/AR) and setup the partnership between
> > the SP/AR and the IdP/AA?
>
> Well, the IDP provides SSO to (and data about) the subject, so for the
> IDP to do anything useful you need Relying Parties (Service Provider)
> that "rely" on that data asserted by the IDP, yes.
>
> You didn't mention the protocol you want the IDP and SP to speak but
> the Shibboleth IDP comes with SAML 2.0 WebSSO out of the box and has
> plugins for OpenID Connect (and can also support CAS).
>
> The Shibboleth SP supports SAML. If you want a webserver-based OIDC RP
> (like the Shibboleth SP is) have a look at https://openidc.org/
>
> HTH,
> -peter
> --
> For Consortium Member technical support, see
> https://shibboleth.atlassian.net/wiki/x/ZYEpPw
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20250325/1e5958a3/attachment.htm>
More information about the users
mailing list