<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<div style="font-family: Calibri, Helvetica, sans-serif; font-size: 12pt">I too hesitate to add another service behind the IdP that has to be maintained, clustered, monitored, etc, but I guess that may be the only option.<br>
</div>
</div>
<div style="font-family: Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Have there been any thoughts around adding a write-back capability to the LDAP attribute store so that the consent records could be stored in an LDAP in a single multivalued attribute?
<br>
</div>
<br>
<div id="Signature">
<div id="divtagdefaultwrapper" dir="ltr" style="font-size:12pt; color:#000000; font-family:Calibri,Helvetica,sans-serif">
<div dir="ltr" style="font-size:12pt; color:#000000; background-color:#FFFFFF; font-family:Calibri,Arial,Helvetica,sans-serif">
<div name="divtagdefaultwrapper" style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:; margin:0">
<div>
<div>Respectfully,</div>
<div>Mark</div>
<div style="font-size:13px; font-family:Tahoma"><br>
<b>Mark McCoy</b><br>
<font size="2" face="Tahoma">OIT Manager, Platform Application Services</font></div>
<div style="font-size:13px; font-family:Tahoma"><font size="2" face="Tahoma">Office of Information Technology<br>
The University of Texas at San Antonio</font></div>
</div>
</div>
</div>
</div>
</div>
<div id="appendonsend"></div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Cantor, Scott <cantor.2@osu.edu><br>
<b>Sent:</b> Friday, April 19, 2019 15:50<br>
<b>To:</b> Shib Users<br>
<b>Subject:</b> RE: Pros and cons of various Consent storage methods</font>
<div> </div>
</div>
<div class="BodyFragment"><font size="2"><span style="font-size:11pt;">
<div class="PlainText">> Can anyone speak to the pros and cons of each of the three methods for storing<br>
> the consent records (client-storage, memcached, database)? What are people<br>
> using and what experiences have you had?<br>
<br>
I would think "real" use of consent means having a database, non-persistent consent doesn't really make much sense. Memcache doesn't seem relevant to this feature at all. That renders consent a non-starter to me, but that's for others to say. I won't put a
database behind my IdP sooner than a day from my retirement.<br>
<br>
The point of client-side is that it's possible to do terms-of-user style "blanket" approvals via the basic feature design that could be used as a per-device "remember my choice" sort of thing that is at least a form of consent but doesn't need a database. I
was planning to do something like that at OSU for FERPA overrides but our registrar overruled me and we left it at nothing, we just block release. Not my call, but I think it would have worked reasonably.<br>
<br>
Using it for "full" consent is more a toy and a way to test out the feature than a practical idea. It is a feat of technical engineering that I made it work with no impact on the code at all and I'm pleased that it did, but it isn't practical.<br>
<br>
-- Scott<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://nam03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwiki.shibboleth.net%2Fconfluence%2Fx%2FcoFAAg&data=02%7C01%7Cmark.mccoy%40utsa.edu%7Cf751c899a8f3405a803c08d6c508a2e2%7C3a228dfbc64744cb88357b20617fc906%7C0%7C0%7C636913038227037050&sdata=Gus97n9Tc6Xp7GpJtkYmPxF4pw6uZAGByjMxyuihB18%3D&reserved=0">
https://nam03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwiki.shibboleth.net%2Fconfluence%2Fx%2FcoFAAg&data=02%7C01%7Cmark.mccoy%40utsa.edu%7Cf751c899a8f3405a803c08d6c508a2e2%7C3a228dfbc64744cb88357b20617fc906%7C0%7C0%7C636913038227037050&sdata=Gus97n9Tc6Xp7GpJtkYmPxF4pw6uZAGByjMxyuihB18%3D&reserved=0</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font></div>
</body>
</html>