Skip to Content.
Sympa Menu

shibboleth-dev - Re: Gridshib profile

Subject: Shibboleth Developers

List archive

Re: Gridshib profile


Chronological Thread 
  • From: Tom Scavo <>
  • To: Von Welch <>
  • Cc: Thomas Lenggenhager <>,
  • Subject: Re: Gridshib profile
  • Date: Fri, 4 Mar 2005 13:20:16 -0500
  • Domainkey-signature: a=rsa-sha1; q=dns; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:reply-to:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:references; b=g5+piZtRG9myxYr/bZijn2uf0tT0LWVFQL16Azb8L68w8w2GEGhdsYxY49i5+hfKnfufUzw9UDKIwSanIbW6WwJkDlb3wJ+e7Lo3Udg5A5cMgS3Udf9zjTXL+LdFk9n2EXaYRiuxQ0qT8+CAZlEMzViKZcAIQCd2eITpDRksiBg=

On Thu, 3 Mar 2005 18:44:32 -0600, Von Welch
<>
wrote:
>
> You are correct in your understanding that the Grid Service would
> need to be listed in the ARP and I agree adding that to our profile
> would help.

ARPs are a deployment tool not a profile consideration, so yes, we
should address this issue in the GridShib deployment documentation.
On the other hand, the profile should specify security considerations,
which currently we do not do.

Thomas' point is well taken, however. We must mitigate the
possibility that a grid service could request attributes for any user.
Perhaps there is some comfort in the fact that the DN in the proxy
cert is short-lived, so if we make sure that the DN binding at the IdP
expires along with the proxy cert, this is good enough.

As Thomas suggests, if we can solve the pseudonymous GridShib use
case, this problem goes away.

> > Shibbolizing Grid and LionShare services that way

Remember, GridShib and LionShare are different in that a LionShare
peer pushes attributes. In the case of LionShare, user policy is
ignored since the user is requesting its own attributes.

Up to now, GridShib hasn't seriously considered attribute push. We
should. It solves a bunch of problems simultaneously..

> > would require the
> > availability of end-user tools with which a user would be able to
> > configure his/her user specific ARP easily.
>
> I believe all the ARP management tools I've seen are mean to be run by
> the IdP admin. Do any user tools exist?

I've seen a detailed specification and know of at least two people who
have or are working on this. Don't know the current status, however.
(Steven Carmody would know.)

Tom



Archive powered by MHonArc 2.6.16.

Top of Page