Skip to Content.
Sympa Menu

shibboleth-dev - RE: Scope of self

Subject: Shibboleth Developers

List archive

RE: Scope of self


Chronological Thread 
  • From: "Scott Cantor" <>
  • To: <>
  • Subject: RE: Scope of self
  • Date: Fri, 4 Nov 2005 15:38:29 -0500
  • Organization: The Ohio State University

> How can a name mapping plugin know shibmd:Scope if the IdP does not
> consume its own metadata?

It doesn't know it. The only place scope is ever mentioned is inside the
attribute resolver. Name Identifiers aren't "scoped" and there is no code
that could filter them using the metadata anyway. Whether this is a problem
or not probably depends on whether this scoped stuff was a good idea at all,
but I guess I'll revisit it when I have to recode all of that stuff for 2.0.

Regardless, consuming your own metadata is never a requirement for anything.
You can always configure the information directly. I don't see how listing a
bunch of scopes out could be used to configure this anyway. The issue isn't
what scopes are allowed but which one to use, so how could you tell which
one to use?

-- Scott




Archive powered by MHonArc 2.6.16.

Top of Page