shibboleth-dev - RE: [Shib-Dev] [IdPv3] Consent Engine Work
Subject: Shibboleth Developers
List archive
- From: "Scott Cantor" <>
- To: <>
- Subject: RE: [Shib-Dev] [IdPv3] Consent Engine Work
- Date: Mon, 27 Sep 2010 10:43:54 -0400
- Organization: The Ohio State University
> Yes, I was talking about SAML V2.0 persistent name ID. That needs to
> be redundantly asserted as an attribute for consent to work, right?
Depends how the NameID selection process is related to consent, I suppose.
But I don't really see that concept as something that works well with
consent or can be explained effectively to users.
> I'm not sure what you mean. This is a real requirement articulated
> clearly by Federation SPs (well, at least one Federation SP :)
By some SPs.
> I don't think that helps much. A specific example is ePTID vs EPPN. If
> an institution does not reassign EPPNs, the SP probably wouldn't care
> which it receives. How does the SP communicate that to the IdP (short
> of defining a new, abstract attribute)?
By not worrying about it too much, asking for either/or and living with the
result. If you need persistence, you can't use EPPN, seems to me, without
additional machinery. Pragmatically, most sites will give up persistence in
favor of usability, and I don't see the number of sites willing to support
anything but EPPN growing very much.
-- Scott
- RE: [Shib-Dev] [IdPv3] Consent Engine Work, (continued)
- RE: [Shib-Dev] [IdPv3] Consent Engine Work, Scott Cantor, 09/24/2010
- Re: [Shib-Dev] [IdPv3] Consent Engine Work, Tom Scavo, 09/24/2010
- RE: [Shib-Dev] [IdPv3] Consent Engine Work, Scott Cantor, 09/24/2010
- Re: [Shib-Dev] [IdPv3] Consent Engine Work, Tom Scavo, 09/25/2010
- Re: [Shib-Dev] [IdPv3] Consent Engine Work, Chad La Joie, 09/25/2010
- Re: [Shib-Dev] [IdPv3] Consent Engine Work, Tom Scavo, 09/25/2010
- RE: [Shib-Dev] [IdPv3] Consent Engine Work, Scott Cantor, 09/25/2010
- Re: [Shib-Dev] [IdPv3] Consent Engine Work, Tom Scavo, 09/27/2010
- RE: [Shib-Dev] [IdPv3] Consent Engine Work, Scott Cantor, 09/27/2010
- Re: [Shib-Dev] [IdPv3] Consent Engine Work, Tom Scavo, 09/27/2010
- RE: [Shib-Dev] [IdPv3] Consent Engine Work, Scott Cantor, 09/27/2010
- RE: [Shib-Dev] [IdPv3] Consent Engine Work, Scott Cantor, 09/27/2010
- Re: [Shib-Dev] [IdPv3] Consent Engine Work, Chad La Joie, 09/25/2010
- Re: [Shib-Dev] [IdPv3] Consent Engine Work, Tom Scavo, 09/25/2010
- RE: [Shib-Dev] [IdPv3] Consent Engine Work, Scott Cantor, 09/24/2010
Archive powered by MHonArc 2.6.16.