Skip to Content.
Sympa Menu

shibboleth-dev - RE: Future of the WAYF discussion

Subject: Shibboleth Developers

List archive

RE: Future of the WAYF discussion


Chronological Thread 
  • From:
  • To:
  • Subject: RE: Future of the WAYF discussion
  • Date: Wed, 28 Sep 2005 09:58:52 -0400

> At this stage if one postulates a SAML_IDP cookie aware SP and possibly a
mechanism to manage the SAML_IDP cookie (maybe a browser plugin?) then we
should get to a situation when the user only sees the WAYF when they
genuinely have to set about discovering a new Identity Service.

Except on shared machines. Quite a lot of people punt at this point, but if
we keep trying to solve the unsolvable, we won't get anywhere. The only way
to address shared machines is with the client.


on campuses, anyway, one of the largest sources of shared machines are the public clusters. Increasingly, tho, it seems if you walk into one of these clusters, you have to login in order to use the machine. I've heard some campuses talk about including the appropriate cookie in the refresh image used to maintain these machines. This does have the downside that Thomas mentions (suppose someone was able to authenticate locally, but actually wanted to use an IdP other than the campus). Interesting tradeoff, tho, when you think about the technical knowledge level of most of the people using these public clusters....



Archive powered by MHonArc 2.6.16.

Top of Page