<div dir="ltr"><div class="gmail_quote"><div dir="ltr">On Fri, Aug 10, 2018 at 4:47 PM Cantor, Scott <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>> wrote:</div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
> What's the risk of allowing this reverse lookup?<br>
<br>
Nothing really unless you allow Attribute Queries, then it provides direct access to whatever data is released to that SP based on that ID. You can think of it like a pseudo-token that effectively authorizes access to attributes about that subject.<br></blockquote><div><br></div><div>Thank you for clarifying that, which is exactly what I was wondering. In our particular case where we scope to trusted relying parties, that risk is acceptable.</div><div><br></div><div>Best,</div><div>M<a href="mailto:users-unsubscribe@shibboleth.net" target="_blank"></a><br>
</div><div><br></div></div></div>