mace-opensaml-users - RE: SAML for Provisioning
Subject: OpenSAML user discussion
List archive
- From: "Scott Cantor" <>
- To: "'Tom Scavo'" <>, "'Prasad'" <>
- Cc: <>
- Subject: RE: SAML for Provisioning
- Date: Thu, 29 Sep 2005 17:25:25 -0400
- Organization: The Ohio State University
> Prasad, can you explain a bit more what you mean by "user
> provisioning"? Surely, a SAML service provider might create a user
> account on the basis of a (strong) SAML assertion returned from a
> (trusted) SAML identity provider, but that seems to defeat the purpose
> of a SAML browser profile altogether.
Why? That's probably a good summation of a majority of the actual
deployments out there, except that they probably don't create the account at
the time of login, it's in advance.
In the sense that you can dynamically provision based on attributes/claims,
that's certainly an obvious use of SAML to do "provisioning". One might also
lump name identifier mgmt into the provisioning category (it was one reason
some of the TC didn't want to do it).
The original Shib idea of "send only attributes, grant transitory access"
seems to be the minority, not the primary use case. Today anyway.
-- Scott
- SAML for Provisioning, Prasad, 09/29/2005
- Re: SAML for Provisioning, Tom Scavo, 09/29/2005
- RE: SAML for Provisioning, Scott Cantor, 09/29/2005
- Re: SAML for Provisioning, Mark Allen Earnest, 09/29/2005
- RE: SAML for Provisioning, Scott Cantor, 09/29/2005
- Re: SAML for Provisioning, RL 'Bob' Morgan, 09/29/2005
- Re: SAML for Provisioning, Prasad, 09/29/2005
- <Possible follow-up(s)>
- Re: SAML for Provisioning, Chad La Joie, 09/29/2005
- Re: SAML for Provisioning, Prasad, 09/29/2005
- Re: SAML for Provisioning, Tom Scavo, 09/29/2005
Archive powered by MHonArc 2.6.16.