Re: [saml-dev] IdP DS Protocol and Profile

From
Dhad Ma Koie
Date
2010-09-30T19:45:59+00:00
ID
AANLkTinAR9=
Thread
Re: [saml-dev] IdP DS Protocol and Profile
You don't need a policy for that.  The DS request contains the entity
ID of the SP and the DS has metadata so it can look up the metadata
for the SP and filter the IdPs based on that if it really cares.

Most SPs though would give a much better user experience if they owned
the DS and then only listed IdPs with which is was willing to work
(i.e. its "customers").

On Thu, Sep 30, 2010 at 21:37, Tom Scavo <> wrote:
> On Thu, Sep 30, 2010 at 11:57 AM, Scott Cantor <> wrote:
>> BTW, the DS protocol is SSO protocol agnostic. Using it doesn't imply any
>> particular SAML version (or SAML at all) between the SP and the selected
>> IdP. That was one of the possible extensions that might involve the policy
>> parameter, some way to filter the result by supported protocol, but the
>> basic protocol ignores that use case.
>
> You read my mind! The idea was that an SP could give the DS a hint as
> to what protocols it supported. I spoke with Lukas H鄝merle
> (maintainer of the SWITCH DS) about this but he's inclined to parse
> the metadata just-in-time (which makes sense actually).
>
> Tom
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: 
> For additional commands, e-mail: 
>
>

-- 
Chad La Joie
www.itumi.biz
trusted identities, delivered