shibboleth-dev - Re: authentication authority
Subject: Shibboleth Developers
List archive
- From: Chad La Joie <>
- To:
- Subject: Re: authentication authority
- Date: Fri, 07 Oct 2005 20:24:25 -0400
- Organization: UIS - Project Sentinel
Scott Cantor wrote:
My issue with this approach, if I understand the mechanics correctly, and this is purely an issue with today's implementations - is that the Shib AA demuxes on the Format attribute to call the appropriate namemapper plugin. Since the encrypted handle approach shares with the default Shib Handle, in practice this means a Shib IdP can do one or the other. Meaning if we go this route, folks have to use a non- default IdP configuration (encrypted vs regular handles).
Nobody uses the memory implementation today if they're serious about the
software. It's not usable in a cluster, and this is a service that has to be
reliable. Chad's extension is a possible alternative, but even then I think
it's a replacement/extension for the in-memory mapper, though I could be
wrong about that.
Correct, the HA-Shib extension offers replacements for the Name and Artifact mapper functions. It stores it's information in-memory but replicates states across cluster nodes (so all the in-memory state on all the nodes is synched).
--
Chad La Joie 315Q St. Mary's Hall
Project Sentinel 202.687.0124
- RE: authentication authority, (continued)
- RE: authentication authority, Scott Cantor, 10/04/2005
- Re: authentication authority, Von Welch, 10/04/2005
- RE: authentication authority, Scott Cantor, 10/04/2005
- Re: authentication authority, Von Welch, 10/04/2005
- Re: authentication authority, RL 'Bob' Morgan, 10/04/2005
- Re: authentication authority, Von Welch, 10/04/2005
- RE: authentication authority, Scott Cantor, 10/04/2005
- Re: authentication authority, Tom Scavo, 10/05/2005
- RE: authentication authority, Scott Cantor, 10/06/2005
- Re: authentication authority, Von Welch, 10/07/2005
- RE: authentication authority, Scott Cantor, 10/07/2005
- Re: authentication authority, Chad La Joie, 10/07/2005
- Re: authentication authority, Von Welch, 10/09/2005
- Re: authentication authority, Von Welch, 10/07/2005
- Re: authentication authority, Tom Scavo, 10/08/2005
- Re: authentication authority, Scott Cantor, 10/08/2005
- Re: authentication authority, Tom Scavo, 10/10/2005
- RE: authentication authority, Scott Cantor, 10/10/2005
- Re: authentication authority, Tom Scavo, 10/12/2005
- RE: authentication authority, Scott Cantor, 10/13/2005
- Re: authentication authority, Tom Scavo, 10/13/2005
- Re: authentication authority, Scott Cantor, 10/13/2005
- Re: authentication authority, Tom Scavo, 10/14/2005
- RE: authentication authority, Scott Cantor, 10/06/2005
- Re: authentication authority, Tom Scavo, 10/05/2005
- RE: authentication authority, Scott Cantor, 10/04/2005
- Re: authentication authority, Von Welch, 10/04/2005
- RE: authentication authority, Scott Cantor, 10/04/2005
Archive powered by MHonArc 2.6.16.