Problem trying to add an additional partner to my Shibboleth IdP
Cantor, Scott
cantor.2 at osu.edu
Mon May 5 13:31:32 UTC 2025
The "right" way to operate the IdP at any scale is to develop a scripted mechanism for generating metadata for SPs that are not trustable via a federation, and use tags in the metadata (or applied via metadata filters) to drive most of the IdP's configuration, including attribute release.
The majority of the IdP configuration outside the authentication and attribute resolver features at this point is legacy, from before the support for metadata-driven configuration was developed. Nowadays, you just touch the metadata and ignore everything elwe day to day.
Filters now are best used for edge cases or more advanced policies that aren't simple enough for tag-driven rules.
Unicon also developed a metadata management GUI that can be used for those who for whatever reason don't prefer scripting. I don't know where it lives officially but I'm sure somebody can point to it.
-- Scott
More information about the users
mailing list