Skip to Content.
Sympa Menu

shibboleth-dev - RE: wrt user entry of a pointer to their IDP ..or.. "invisible SSO"

Subject: Shibboleth Developers

List archive

RE: wrt user entry of a pointer to their IDP ..or.. "invisible SSO"


Chronological Thread 
  • From: "Scott Cantor" <>
  • To: <>
  • Subject: RE: wrt user entry of a pointer to their IDP ..or.. "invisible SSO"
  • Date: Thu, 20 Sep 2007 11:29:10 -0400
  • Organization: The Ohio State University

> I have been told by colleagues in the schools sector that some
> categories of user, such as young children, simply aren't capable of
> selecting 'their' IdP. Whether the selection UI is located at the SP or
> some other WAYF (or indeed as a piece of browser chrome) is moot.

This is an example of what bothers me....is the message there "forget it"?
Because I don't see how to turn that feedback into a proposal.

> Even for adult users, the answer to the question "which IdP are you
> affiliated with" is not always obvious; for example, there are cases
> concerning multiple affiliations and the correct answer depends on the
> user knowing which IdP has the relevant relationship with the SP for the
> resource in question.

True, though I have yet to see that materialize in practice, but this is, I
think, an argument for the process being closer to the SP, not farther away.

> It gets worse when we ask the question "which
> federation is your IdP affiliated with" because the user has no concept
> of federation.

And I think most agree that's a dead end.

-- Scott





Archive powered by MHonArc 2.6.16.

Top of Page