shibboleth-dev - RE: Attributes, and Shibboleth -- the EPPN swamp
Subject: Shibboleth Developers
List archive
- From: "Scott Cantor" <>
- To: "'RL 'Bob' Morgan'" <>, "'Shibboleth Project'" <>
- Cc: "'MACE-Dir'" <>, "'Shibboleth Design Team'" <>
- Subject: RE: Attributes, and Shibboleth -- the EPPN swamp
- Date: Fri, 25 Jan 2002 14:18:43 -0500
- Importance: Normal
- Organization: The Ohio State University
> origin-site: washington.edu
> security-domain-list: u.washington.edu
> So, the washington.edu institutional directory publishes
> EPPNs like
> ""
> (yes, it really is "u."
> for historical reasons, there is no defined "washington.edu"
> security domain at this point). The washington.edu AA
> asserts attributes and values with the semantics:
>
> eppn: local-part="rlmorgan", security-domain="u.washington.edu"
> affiliation: local-part="staff", security-domain="u.washington.edu"
All of this looks good to me with a question remaining about what
SecurityDomain to put in the assertion subject. My assumption is that
it's the name of the origin site and not the security domain of, say,
the user's EPPN. Even if all the user's attributes have to override the
scope to be u.washington.edu, I still think that's better.
I seem to recall we hit that question on the last call, but I can't
remember what the point of disagreement was or what I was thinking of at
the time.
For one thing, if you follow the line of logic at the end of your
proposal to having two origins issuing attributes in the same domain,
you can't map back from it to the origin site when you get the assertion
at the SHIRE. So that would pretty much dictate that it be the one, true
origin site name.
-- Scott
------------------------------------------------------mace-shib-design-+
For list utilities, archives, subscribe, unsubscribe, etc. please visit the
ListProc web interface at
http://archives.internet2.edu/
------------------------------------------------------mace-shib-design--
- Attributes, and Shibboleth -- the EPPN swamp, Steven_Carmody, 01/18/2002
- RE: Attributes, and Shibboleth -- the EPPN swamp, Scott Cantor, 01/19/2002
- RE: Attributes, and Shibboleth -- the EPPN swamp, David L. Wasley, 01/23/2002
- RE: Attributes, and Shibboleth -- the EPPN swamp, Scott Cantor, 01/23/2002
- RE: Attributes, and Shibboleth -- the EPPN swamp, Paul B. Hill, 01/23/2002
- RE: Attributes, and Shibboleth -- the EPPN swamp, Steven_Carmody, 01/23/2002
- RE: Attributes, and Shibboleth -- the EPPN swamp, Paul B. Hill, 01/23/2002
- RE: Attributes, and Shibboleth -- the EPPN swamp, David L. Wasley, 01/23/2002
- RE: Attributes, and Shibboleth -- the EPPN swamp, RL 'Bob' Morgan, 01/24/2002
- RE: Attributes, and Shibboleth -- the EPPN swamp, RL 'Bob' Morgan, 01/25/2002
- RE: Attributes, and Shibboleth -- the EPPN swamp, Scott Cantor, 01/25/2002
- RE: Attributes, and Shibboleth -- the EPPN swamp, RL 'Bob' Morgan, 01/25/2002
- RE: Attributes, and Shibboleth -- the EPPN swamp, RL 'Bob' Morgan, 01/24/2002
- RE: Attributes, and Shibboleth -- the EPPN swamp, David L. Wasley, 01/25/2002
- RE: Attributes, and Shibboleth -- the EPPN swamp, RL 'Bob' Morgan, 01/28/2002
- RE: Attributes, and Shibboleth -- the EPPN swamp, Steven_Carmody, 01/23/2002
- RE: Attributes, and Shibboleth -- the EPPN swamp, Paul B. Hill, 01/23/2002
- RE: Attributes, and Shibboleth -- the EPPN swamp, Scott Cantor, 01/23/2002
- RE: Attributes, and Shibboleth -- the EPPN swamp, David L. Wasley, 01/23/2002
- RE: Attributes, and Shibboleth -- the EPPN swamp, Steven_Carmody, 01/23/2002
- RE: Attributes, and Shibboleth -- the EPPN swamp, David L. Wasley, 01/23/2002
- RE: Attributes, and Shibboleth -- the EPPN swamp, Scott Cantor, 01/19/2002
Archive powered by MHonArc 2.6.16.