Skip to Content.
Sympa Menu

edugain-discuss - Re: [eduGAIN-discuss] SPs with no attribute requirements (or so it seems)

edugain-discuss AT lists.geant.org

Subject: An open discussion list for topics related to the eduGAIN interfederation service.

List archive

Re: [eduGAIN-discuss] SPs with no attribute requirements (or so it seems)


Chronological Thread 
  • From: Ian Young <ian AT iay.org.uk>
  • To: Niels van Dijk <niels.vandijk AT surfnet.nl>
  • Cc: edugain-discuss AT geant.net
  • Subject: Re: [eduGAIN-discuss] SPs with no attribute requirements (or so it seems)
  • Date: Thu, 27 Mar 2014 11:26:35 +0000
  • List-archive: <https://mail.geant.net/mailman/private/edugain-discuss/>
  • List-id: eduGAIN discussion list <edugain-discuss.geant.net>


On 27 Mar 2014, at 11:09, Niels van Dijk <niels.vandijk AT surfnet.nl> wrote:

> But (perhaps putting it a bit bluntly): in our effort to lower the
> amount of work for the SP have we perhaps taken away the opportunity to
> fix the problem when it was still small (fix/upgrade a bit of config in
> the SP) to a place where it is become big: multiple IdPs and federation
> having to do the checking time and time again?

It's a judgement call, and we can reasonably disagree about which way to make
the call. From where I'm standing, it probably looks like more work to get to
100% than it would be for a federation which has traditionally been recording
this information (and I won't get into the tedious history behind why we
didn't start doing this earlier).

The balance between the work required (which is *not* primarily SP
configuration change, but a dialog between the fedop and in our case each of
900 individual SP operators) and the benefit delivered (taking into account
the limitations of the SAML format to accurately deliver a picture of the
SP's real requirements) is going to look very different to different
federation operators.

Put yet another way, I'd say that the root difficulty in all interfederation
discussions is that for any value of "you", not everyone is like you.

-- Ian



Attachment: smime.p7s
Description: S/MIME cryptographic signature




Archive powered by MHonArc 2.6.19.

Top of Page