shibboleth-dev - Re: release of authentication assertion
Subject: Shibboleth Developers
List archive
- From: Thomas Lenggenhager <>
- To:
- Subject: Re: release of authentication assertion
- Date: Fri, 22 Sep 2006 07:34:30 +0200
- Organization: SWITCH
Scott Cantor wrote:
>> like we need is not just an "Attribute Release Policy", but rather an
>> "Assertion Release Policy".
>
> That's what endpoint checking is, we just don't have an option to disallow
> unidentified providers from being allowed. It's already going to be added
> per the request of the Swiss among others.
Thank you, looking forward to deploy it!
> I'd like to note that this basic aspect of SAML deployment (some products
> don't allow anonymous requests) is viewed by some communities as a bad
> thing, because it forces the user to be at the mercy of the IdP when it
> comes to which services to access.
I surely see a reason for that behavior especially for independent IdP
services. For university IdP denying anonymous use seems more likely for me.
Getting an authentication assertion from a university IdP implies that
the user is most likely an academic user, without sending an attribute.
With an independent IdP nothing comparable can be deducted.
Thomas
--
Thomas Lenggenhager http://www.switch.ch/
SWITCH The Swiss Education & Research Network
Zurich, Switzerland Tel: +41 44 268 1541
- release of authentication assertion, Will Norris, 09/21/2006
- RE: release of authentication assertion, Scott Cantor, 09/21/2006
- Re: release of authentication assertion, Walter Hoehn, 09/21/2006
- Re: release of authentication assertion, Thomas Lenggenhager, 09/22/2006
- RE: release of authentication assertion, Scott Cantor, 09/22/2006
- Re: release of authentication assertion, Velpi, 09/22/2006
- RE: release of authentication assertion, Scott Cantor, 09/22/2006
- Re: release of authentication assertion, Brendan Bellina, 09/22/2006
- RE: release of authentication assertion, Scott Cantor, 09/22/2006
- Re: release of authentication assertion, Brendan Bellina, 09/22/2006
- RE: release of authentication assertion, Scott Cantor, 09/22/2006
- RE: release of authentication assertion, Scott Cantor, 09/21/2006
Archive powered by MHonArc 2.6.16.