shibboleth-dev - RE: Attribute Exchange Profile
Subject: Shibboleth Developers
List archive
- From: "Scott Cantor" <>
- To: <>
- Subject: RE: Attribute Exchange Profile
- Date: Wed, 16 Nov 2005 16:50:04 -0500
- Organization: The Ohio State University
> What about the case of an IdP that requests and obtains attributes
> from other IdPs? I don't have a specific use case, but should we not
> rule out the possibility?
I should say since it's on the subject that when asked, I've said repeatedly
that even though it looks more invasive to handle this at the SP, I think
it's much cleaner to query multiple sources and do identifier mapping there,
and leave the trust relationships and policies point to point instead of
artificially introducing proxying and delegation of authority into the
picture prematurely.
I'm thinking long and hard about how to structure the SP for 2.0 to make
adding that possible at some point.
-- Scott
- Attribute Exchange Profile, Tom Scavo, 11/16/2005
- RE: Attribute Exchange Profile, Scott Cantor, 11/16/2005
- Re: Attribute Exchange Profile, Tom Scavo, 11/16/2005
- RE: Attribute Exchange Profile, Scott Cantor, 11/16/2005
- Re: Attribute Exchange Profile, Tom Scavo, 11/16/2005
- RE: Attribute Exchange Profile, Scott Cantor, 11/16/2005
- Re: Attribute Exchange Profile, Tom Scavo, 11/16/2005
- RE: Attribute Exchange Profile, Scott Cantor, 11/16/2005
- RE: Attribute Exchange Profile, Scott Cantor, 11/16/2005
- Re: Attribute Exchange Profile, Tom Scavo, 11/16/2005
- RE: Attribute Exchange Profile, Scott Cantor, 11/16/2005
- Re: Attribute Exchange Profile, Tom Scavo, 11/16/2005
- RE: Attribute Exchange Profile, Scott Cantor, 11/16/2005
- Re: Attribute Exchange Profile, Tom Scavo, 11/16/2005
- RE: Attribute Exchange Profile, Scott Cantor, 11/16/2005
Archive powered by MHonArc 2.6.16.