Skip to Content.
Sympa Menu

shibboleth-dev - RE: [Shib-Dev] IdP attribute release

Subject: Shibboleth Developers

List archive

RE: [Shib-Dev] IdP attribute release


Chronological Thread 
  • From: "Alistair Young" <>
  • To:
  • Subject: RE: [Shib-Dev] IdP attribute release
  • Date: Tue, 18 Nov 2008 17:07:03 -0000 (GMT)
  • Importance: Normal

righto - saw that in the logs but it didn't seem to tie into any decision
making process. By authenticated, do you mean the sp has to sign the
attribute query? Or does the IdP authenticate based on the x509 from the
ssl connection? I'm presuming the IdP only consumes uk fed metadata so I
can think of at least one route to investigate.

Yes Ian, correct on that one. I suspect perhaps the sp's metadata isn't in
the fed metadata but I'll pursue that elsewhere.

cheers,

Alistair


--
mov eax,1
mov ebx,0
int 80h

>> A Shibboleth IdP won't (can't) release ePTI to an SP that hasn't been
>> authenticated, for example because it hasn't provided a credential on
>> the attribute callback.
>
> Yes, that's true. It's acceptable (though unlikely to be a good idea) to
> put
> it in the default ARP, but that's one case where having it there won't
> work
> if the request is anonymous. That falls into the "not successfully
> resolved"
> bucket I mentioned in the last email.
>
> If the logs aren't clearly indicating that, I'd file a bug.
>
> -- Scott
>
>
>




Archive powered by MHonArc 2.6.16.

Top of Page