On Thu, Sep 30, 2010 at 11:57 AM, Scott Cantor <> wrote:
> BTW, the DS protocol is SSO protocol agnostic. Using it doesn't imply any
> particular SAML version (or SAML at all) between the SP and the selected
> IdP. That was one of the possible extensions that might involve the policy
> parameter, some way to filter the result by supported protocol, but the
> basic protocol ignores that use case.
You read my mind! The idea was that an SP could give the DS a hint as
to what protocols it supported. I spoke with Lukas H鄝merle
(maintainer of the SWITCH DS) about this but he's inclined to parse
the metadata just-in-time (which makes sense actually).
Tom