<br /><span>On 23/02/12, <b class="name">&quot;Cantor, Scott&quot; </b> &lt;cantor.2@osu.edu&gt; wrote:</span><blockquote cite="mid:CB6B0231.15C60%cantor.2@osu.edu" class="iwcQuote" style="border-left: 1px solid rgb(0, 0, 255); padding-left: 13px; margin-left: 0pt;" type="cite"><div class="mimepart text plain">&gt;I agree, however I'm failing to see another way to accomplish the task I<br />&gt;have been set.<br />&gt;In an ideal world I'm guessing that I would set some values for<br />&gt;eduPersonEntitlement indicating whether the user was allowed acces to the<br />&gt;resource and agree these with the SP's?<br /><br />Whether you call it an entitlement or something else, that's how you do<br />it. Whether you call it &quot;affiliation=student&quot; or &quot;entitlement=foo&quot;, you<br />end up with the same outcome, the difference being that one is intended to<br />be calculated based on the user + service, and the other is not defined<br />that way.</div></blockquote>I'm not sure what you mean here, can you explain further in layman's terms?<br /><blockquote cite="mid:CB6B0231.15C60%cantor.2@osu.edu" class="iwcQuote" style="border-left: 1px solid rgb(0, 0, 255); padding-left: 13px; margin-left: 0pt;" type="cite"><div class="mimepart text plain"><br /><br />Even if you force every entitlement in the world to be one value to avoid<br />having to argue over what the value should be, setting that per-service is<br />better than the alternative of misusing other attributes.<br /><br />The problem with the anything-goes approach to attributes is that it<br />presupposes everybody working with some SP is willing to accept that. When<br />those of us already using some strategy for affiliation that meets the<br />intention of the attribute try and push back, the SP says &quot;why are you<br />being so difficult, everybody else is fine with it&quot;.</div></blockquote>Yes, I'd rather use something standards-based so it's easier to maintain in the long run.<br /><br />Thanks for your help with this,<br />-Keith<br /><blockquote cite="mid:CB6B0231.15C60%cantor.2@osu.edu" class="iwcQuote" style="border-left: 1px solid rgb(0, 0, 255); padding-left: 13px; margin-left: 0pt;" type="cite"><div class="mimepart text plain"><br /><br />There's also the fact that some sites have reasonable directories and<br />back-end systems, and they want to be able to store these attributes<br />directly rather than mocking them all up on the fly based on the service<br />identity. They can't do that if everybody devolves to using attributes<br />that don't allow for this.<br /><br />&gt;The problem I can see in this is getting all the SP's to organise and<br />&gt;agree these within the time-frame.<br /><br />You don't need to agree on anything more than what you're already<br />&quot;agreeing&quot; to for it to be at least a little less bad.<br /><br />-- Scott<br /><br />--<br />To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br /></div></blockquote>