<div dir="ltr">Hi,<br><br><div><div class="gmail_extra"><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div>
That isn't possible unless you enabled anonymous RP support. Without<br></div>
metadata it won't work.<br></blockquote><div><br></div><div>I see one line in my RP config that mentions "anonymous:"<br></div><div> <rp:AnonymousRelyingParty provider="<a href="https://shibboleth.brandeis.edu/idp/shibboleth" target="_blank">https://shibboleth.brandeis.edu/idp/shibboleth</a>" defaultSigningCredentialRef="IdPCredential"/><br>
<br></div><div>So I guess I have enabled anonymous RP support. Is that something that is there by default? Regardless…<br></div><div><br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<div>If you don't care about controlling which SPs actually use the IdP, then<br></div>
you don't necessarily need metadata<br></blockquote><div><br></div><div>This gets to the heart of my question. <i>Should</i> I be concerned? <br><br></div><div>What do you mean by SPs that "actually use the IdP"? If I didn't release an attribute to a particularly anonymous SP's entityID then what would happen?<br>
<br><blockquote>but then there are attribute release considerations.<br></blockquote><br>What are the attribute release considerations? I don't think I release attributes to unknown SPs -- and like I said, I used the "anonymous" SP's entityID to release an attribute that they need (which I'm hoping isn't releasing <br>
<br></div><div>Using the aacli.sh bin to test if I use the anonymous SP's entityID I see the attribute I released to them. If I type in jibberish for the requester then it just returns "No attribute statement." I guess this is why I'm confused -- what will creating metadata improve/fix/prevent?<br>
</div><div><br></div><div>Thanks again,<br>Ian<br></div></div></div></div></div>