<br><br><div class="gmail_quote">On Thu, Mar 8, 2012 at 11:05 AM, Keith Hazelton <span dir="ltr"><<a href="mailto:hazelton@doit.wisc.edu">hazelton@doit.wisc.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div class="im">On Thu, 2012-03-08 at 12:59 -0500, Chad La Joie wrote:<br>
> Hey Keith,<br>
><br>
> I'm not quite sure what you're asking. You seem to be suggesting that<br>
> passing a given entitlement value through would be bad but that passing<br>
> affiliation values isn't. I'm not sure I see any difference.<br>
><br>
> If you're interested in a full SAML solution, the answer is fairly easy.<br>
> You delegate through each tier an either the assertion contains<br>
> attributes targeted to the SP or the SP queries for them. Then no one<br>
> gets to see data they weren't supposed to.<br>
<br>
</div>But that's ECP, right? and too few IdPs support ECP endpoints for our<br>
case. Or is there a non-ECP way to do this?<br></blockquote><div><br></div><div>Well, it's more the P part of ECP. I imagine you'd see an increase in endpoints if the project completed implementation of ECP, and more SPs demanded it.</div>
<div><br></div><div>Dave</div><div><br></div><div>-- </div></div>David Langenberg<div>Identity Management</div><div>The University of Chicago</div><br>