Skip to Content.
Sympa Menu

shibboleth-dev - RE: [Shib-Dev] lessons learned from AD FS 2.0

Subject: Shibboleth Developers

List archive

RE: [Shib-Dev] lessons learned from AD FS 2.0


Chronological Thread 
  • From: "Scott Cantor" <>
  • To: <>
  • Subject: RE: [Shib-Dev] lessons learned from AD FS 2.0
  • Date: Mon, 25 Oct 2010 20:05:14 -0400
  • Organization: The Ohio State University

> One thing seems clear, however. If every <md:KeyDescriptor> element in
> metadata had an explicit 'use' attribute, it would be much easier for
> everybody. So, as Ian observed, our tools need to support this (which
> is probably the most important lesson I've learned from all of this).

It's not that they all should have the attribute. That bloats the file
rather badly. The power comes from controlling the attribute, period, so
that the keys can be manipulated as needed. But that takes understanding,
and is prone to mistakes. That's what's more complicated about it.

-- Scott





Archive powered by MHonArc 2.6.16.

Top of Page