Skip to Content.
Sympa Menu

shibboleth-dev - RE: [Shib-Dev] Debugging shibboleth-idp-ext-delegation [SOLVED]

Subject: Shibboleth Developers

List archive

RE: [Shib-Dev] Debugging shibboleth-idp-ext-delegation [SOLVED]


Chronological Thread 
  • From: "Scott Cantor" <>
  • To: <>
  • Cc: "'Halm Reusser'" <>
  • Subject: RE: [Shib-Dev] Debugging shibboleth-idp-ext-delegation [SOLVED]
  • Date: Mon, 26 Jul 2010 13:24:24 -0400
  • Organization: The Ohio State University

> Adding the ID-WSF SSOS profile handler in the default relying party
> solved our problem, but isn't it a bug?
>
> Why should we add this handler to the default relying party, when it is
> accessed only by the ECP client (https://macvt.switch.ch/shibboleth) and
> defined in its own relying party?

I think that's just how Brent did the implementation. The RelyingParty
config is used when the intermediary is acting as the client in order to
authenticate it as a delegate of the user.

I could be wrong, but I seem to recall that the config might get reworked
when the code is eventually merged into 3.0. It is a bit invasive at the
moment. But it's not all that easy to express the policy complexity here.

-- Scott





Archive powered by MHonArc 2.6.16.

Top of Page