Skip to Content.
Sympa Menu

shibboleth-dev - protocols and profiles

Subject: Shibboleth Developers

List archive

protocols and profiles


Chronological Thread 
  • From: Soner Sevinc <>
  • To:
  • Subject: protocols and profiles
  • Date: Tue, 27 Oct 2009 16:32:18 -0400

Hi,
Maybe I should have checked source code first, but would like to see if there is a quick answer.

If I would like to have such an authentication such that SP should allow a resource only if IdP1 AND IdP2 provides certain attributes for a user, where we can increase the number of IdPs, or possibly allow for disjunction of them, as well, then would SAML support such an authorization scheme, or how "easy" would it be to implement it as a new protocol/profile?

To ask it in another way, I see that some protocols/profiles are not implemented yet, at https://spaces.internet2.edu/display/SHIB2/ShibProtocols . For example, back channel support in single logout protocol is still waiting to be implemented. What would you consider to be the problematic part that makes it more time consuming to cover all use cases at http://www.oasis-open.org/committees/download.php/507/draft-sstc-saml-reqs-01.pdf ?

Thanks so much for help,
Soner



Archive powered by MHonArc 2.6.16.

Top of Page