<html><body><div style="color:#000; background-color:#fff; font-family:arial, helvetica, sans-serif;font-size:12pt"><div><span>OK, since I will have to identify the organization through an attribute instead of the entityID, what is an appropriate attribute for doing this that would be reasonable for the hub and spoke based institutions to support?</span></div><div><br></div>  <div style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"> <div style="font-family: 'times new roman', 'new york', times, serif; font-size: 12pt;"> <div dir="ltr"> <hr size="1">  <font size="2" face="Arial"> <b><span style="font-weight:bold;">From:</span></b> Tom Scavo &lt;trscavo@gmail.com&gt;<br> <b><span style="font-weight: bold;">To:</span></b> Shib Users &lt;users@shibboleth.net&gt; <br> <b><span style="font-weight: bold;">Sent:</span></b> Monday, May 13, 2013 2:29 PM<br> <b><span style="font-weight: bold;">Subject:</span></b> Re: School me on hub and spoke
 federations<br> </font> </div> <div class="y_msg_container"><br>On Mon, May 13, 2013 at 5:04 PM, Leif Johansson &lt;<a ymailto="mailto:leifj@sunet.se" href="mailto:leifj@sunet.se">leifj@sunet.se</a>&gt; wrote:<br>&gt;<br>&gt; However (as with any name-constraints-scheme) the more<br>&gt; scopes you have on a single IdP the higher the risk of<br>&gt; anything going wrong.<br><br>Yes, I found one hub-and-spoke federation that had 256 scopes on its<br>IdP Proxy. Clearly scoped attributes (such as eduPersonPrincipalName)<br>are not compatible with hub-and-spoke federations.<br><br>Let me put it another way. In a full mesh federation, the scope helps<br>prevent one IdP from asserting arbitrary identities. In a<br>hub-and-spoke federation, the IdP Proxy is All-Powerful in that it can<br>assert any identity it wants. Indeed, the IdP Proxy is a single point<br>of compromise.<br><br>Tom<br>--<br>To unsubscribe from this list send an email to <a
 ymailto="mailto:users-unsubscribe@shibboleth.net" href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br><br><br></div> </div> </div>  </div></body></html>