<br><br><div class="gmail_quote">On Thu, Mar 8, 2012 at 11:05 AM, Keith Hazelton <span dir="ltr">&lt;<a href="mailto:hazelton@doit.wisc.edu">hazelton@doit.wisc.edu</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div class="im">On Thu, 2012-03-08 at 12:59 -0500, Chad La Joie wrote:<br>
&gt; Hey Keith,<br>
&gt;<br>
&gt; I&#39;m not quite sure what you&#39;re asking.  You seem to be suggesting that<br>
&gt; passing a given entitlement value through would be bad but that passing<br>
&gt; affiliation values isn&#39;t.  I&#39;m not sure I see any difference.<br>
&gt;<br>
&gt; If you&#39;re interested in a full SAML solution, the answer is fairly easy.<br>
&gt;  You delegate through each tier an either the assertion contains<br>
&gt; attributes targeted to the SP or the SP queries for them.  Then no one<br>
&gt; gets to see data they weren&#39;t supposed to.<br>
<br>
</div>But that&#39;s ECP, right? and too few IdPs support ECP endpoints for our<br>
case.  Or is there a non-ECP way to do this?<br></blockquote><div><br></div><div>Well, it&#39;s more the P part of ECP.  I imagine you&#39;d see an increase in endpoints if the project completed implementation of ECP, and more SPs demanded it.</div>
<div><br></div><div>Dave</div><div><br></div><div>-- </div></div>David Langenberg<div>Identity Management</div><div>The University of Chicago</div><br>