Skip to Content.
Sympa Menu

mace-opensaml-users - RE: SAML for Provisioning

Subject: OpenSAML user discussion

List archive

RE: SAML for Provisioning


Chronological Thread 
  • From: "Scott Cantor" <>
  • To: "'Tom Scavo'" <>, "'Prasad'" <>
  • Cc: <>
  • Subject: RE: SAML for Provisioning
  • Date: Thu, 29 Sep 2005 17:25:25 -0400
  • Organization: The Ohio State University

> Prasad, can you explain a bit more what you mean by "user
> provisioning"? Surely, a SAML service provider might create a user
> account on the basis of a (strong) SAML assertion returned from a
> (trusted) SAML identity provider, but that seems to defeat the purpose
> of a SAML browser profile altogether.

Why? That's probably a good summation of a majority of the actual
deployments out there, except that they probably don't create the account at
the time of login, it's in advance.

In the sense that you can dynamically provision based on attributes/claims,
that's certainly an obvious use of SAML to do "provisioning". One might also
lump name identifier mgmt into the provisioning category (it was one reason
some of the TC didn't want to do it).

The original Shib idea of "send only attributes, grant transitory access"
seems to be the minority, not the primary use case. Today anyway.

-- Scott




Archive powered by MHonArc 2.6.16.

Top of Page