edugain-discuss AT lists.geant.org
Subject: An open discussion list for topics related to the eduGAIN interfederation service.
List archive
- From: Glenn Wearen <glenn.wearen AT heanet.ie>
- To: Nicole Harris <harris AT terena.org>
- Cc: edugain-discuss AT geant.net
- Subject: Re: [eduGAIN-discuss] ALL eduGAIN entities in UK federation?
- Date: Wed, 5 Feb 2014 10:26:13 +0000
- List-archive: <https://mail.geant.net/mailman/private/edugain-discuss/>
- List-id: eduGAIN discussion list <edugain-discuss.geant.net>
That's why I said 'reasonably assume' ;-)But trusted metadata + released attributes does not equate to successful login?
The only way this can be achieved is if you know which resources every IdP subscribes too...and that's a shifting concept.
I feel it's a big ask to expect SP's to filter metadata by their own means, hence the circle of trust concept in JAGGER.
Glenn
8F6826A1-F3FE-4148-A8D5-3DE647C598E0 AT heanet.ie">That's a lot of work :-)Our approach in Edugate (implemented in JAGGER) is to provide metadata tailored for each SP (and IdP) based on circles of trust, where eduGAIN is one such circle. We've yet to tailor the metadata for SP's where we know the IdP has set an attribute release policy to match the SP's requirements; but we'll get there eventually.
The real problem is this example below is that SCRAN is relying on the UK federation central WAYF which does not make any of these distinctions. The solution would either be to say the central WAYFs are borked in the age of edugain, or to ensure that federations and services implement elegant fail messages so that users are well informed...which fits in with Brook's comments below.
Although we have to weigh up the likelihood of a user from the Czech Republic finding scran.ac.uk, clicking on 'shibboleth users' (another broken problem) and then finding the UK federation WAYF and finding their IdP in it.
8F6826A1-F3FE-4148-A8D5-3DE647C598E0 AT heanet.ie">Glenn
HEAnet Limited, Ireland's Education and Research Network -1st Floor, 5 George's Dock, IFSC, Dublin 1Registered in Ireland, no 275301 tel: +353-1-6609040 fax: +353-1-6603666
On 5 Feb 2014, at 09:14, Brook Schofield wrote:
Jan,
UK Federation announced that it would become a full production participant of eduGAIN in early December 2013:this is both intentional and a bug. This isn't dissimilar to the DFN-AAI publishing of its metadata into eduGAIN, acutally the reverse of this situation.
I'm sure others will write a much more elegant response than mine - but I've already received an email from a publisher connected to UK Federation that was interested in the metadata entries of other countries appearing in their metadata feed.
This publisher selectively includes IdPs that have subscribed - so the didn't have a problem - but they wanted to ensure that those IdPs could get access to their service.
https://lists.incommon.org/sympa/arc/interfed/2013-10/msg00010.html (message is pasted twice so you can stop reading when déjà vu sets in)
So again it's intentional. If eduID.cz IdPs are interested in accessing Scran or any other services within the UK Federation then you should contact the organisation and encourage their participation in eduGAIN (which they can do by contacting the UK Federation helpdesk - which will fix the bug - at least for that organisation).
-Brook
On 5 February 2014 09:54, Jan Tomášek <jan.tomasek AT cesnet.cz> wrote:
Hello,
we have discovered that UK federation republishes all entities from eduGAIN into their metadata:
http://metadata.ukfederation.org.uk/ukfederation-metadata.xml
but they are not doing oposite. So entites from UK federation are not being republished into eduGAIN.
I think this could confuse users. By a short experimenting I've found SP https://www.scran.ac.uk/ which offer login by using CESNET, Univerzita Karlova v Praze, ... IdP but those login will always fail because https://www.scran.ac.uk/ is not being exported into eduGAIN, our IdP doesn't know about https://www.scran.ac.uk/ and refuses login. Poor user, poor IdP admin who has to explain to users.
Is this intentional or is this a bug?
--
--------------------------------------------------------------
Jan Tomasek aka Semik work: CESNET, z.s.p.o.
http://www.tomasek.cz/ Zikova 4, 160 00 Praha 6
Czech Republic
phone(work): +420 234 680 279 http://www.cesnet.cz/
--
===================================================
Brook Schofield, TERENA Project Development Officer
TERENA Secretariat, Singel 468 D, 1017 AW Amsterdam, The Netherlands
Tel +31 20 530 4488 Fax +31 20 530 4499 Mob +31 65 155 3991
www.terena.org
-- ---------------- Project Development Officer TERENA Singel 468 D Amsterdam, 1017 AW The Netherlands T: +31(0)20 5304488 F: +31(0)20 5304499 mob: +31(0)646 105395
- [eduGAIN-discuss] ALL eduGAIN entities in UK federation?, Jan Tomášek, 05-Feb-2014
- Re: [eduGAIN-discuss] ALL eduGAIN entities in UK federation?, Brook Schofield, 05-Feb-2014
- Re: [eduGAIN-discuss] ALL eduGAIN entities in UK federation?, Glenn Wearen, 05-Feb-2014
- Re: [eduGAIN-discuss] ALL eduGAIN entities in UK federation?, Nicole Harris, 05-Feb-2014
- Re: [eduGAIN-discuss] ALL eduGAIN entities in UK federation?, Glenn Wearen, 02/05/2014
- Re: [eduGAIN-discuss] ALL eduGAIN entities in UK federation?, Nicole Harris, 05-Feb-2014
- Re: [eduGAIN-discuss] ALL eduGAIN entities in UK federation?, Glenn Wearen, 05-Feb-2014
- Re: [eduGAIN-discuss] ALL eduGAIN entities in UK federation?, Alex Stuart, 05-Feb-2014
- Re: [eduGAIN-discuss] ALL eduGAIN entities in UK federation?, Jan Tomášek, 05-Feb-2014
- Re: [eduGAIN-discuss] ALL eduGAIN entities in UK federation?, Tomasz Wolniewicz, 05-Feb-2014
- Re: [eduGAIN-discuss] ALL eduGAIN entities in UK federation?, Nicole Harris, 05-Feb-2014
- Re: [eduGAIN-discuss] ALL eduGAIN entities in UK federation?, Peter Schober, 05-Feb-2014
- Re: [eduGAIN-discuss] ALL eduGAIN entities in UK federation?, Peter Schober, 05-Feb-2014
- Re: [eduGAIN-discuss] ALL eduGAIN entities in UK federation?, Leif Johansson, 05-Feb-2014
- Re: [eduGAIN-discuss] ALL eduGAIN entities in UK federation?, Jan Tomášek, 05-Feb-2014
- Re: [eduGAIN-discuss] ALL eduGAIN entities in UK federation?, Peter Schober, 05-Feb-2014
- Re: [eduGAIN-discuss] ALL eduGAIN entities in UK federation?, Leif Johansson, 05-Feb-2014
- Re: [eduGAIN-discuss] ALL eduGAIN entities in UK federation?, Peter Schober, 05-Feb-2014
- Re: [eduGAIN-discuss] ALL eduGAIN entities in UK federation?, Jan Tomášek, 05-Feb-2014
- Re: [eduGAIN-discuss] ALL eduGAIN entities in UK federation?, Jan Tomášek, 05-Feb-2014
- Re: [eduGAIN-discuss] ALL eduGAIN entities in UK federation?, Brook Schofield, 05-Feb-2014
Archive powered by MHonArc 2.6.19.