Skip to Content.
Sympa Menu

shibboleth-dev - Attribute Queries in Shib 2

Subject: Shibboleth Developers

List archive

Attribute Queries in Shib 2


Chronological Thread 
  • From: Chad La Joie <>
  • To:
  • Subject: Attribute Queries in Shib 2
  • Date: Thu, 05 Jul 2007 11:10:25 -0400
  • Openpgp: id=A260F52E; url=http://pgpkeys.pca.dfn.de/pks/lookup?op=get&search=0x3F5E9E87A260F52E
  • Organization: Georgetown University

I thought others might find it useful.

By default, the Shibboleth 2.0 IdP pushes attributes. It can be
configured to not do this on a per relying party (or relying party
group) basis.

My understanding is that the SP does not query for attributes (ever) if
they are pushed. If they are not pushed, and an attribute authority
role for the IdP is defined, it will query once and then cache the
information for the life of the user's Shib session.

Scott, is the SP information basically correct?
--
Chad La Joie 2052-C Harris Bldg
OIS-Middleware 202.687.0124



Archive powered by MHonArc 2.6.16.

Top of Page