edugain-discuss AT lists.geant.org
Subject: An open discussion list for topics related to the eduGAIN interfederation service.
List archive
- From: Olivier Salaün <olivier.salaun AT renater.fr>
- To: "edugain-discuss AT geant.net" <edugain-discuss AT geant.net>
- Subject: [eduGAIN-discuss] Test/dev IdPs in eduGAIN metadata
- Date: Thu, 16 Apr 2015 13:57:42 +0200
- List-archive: <http://mail.geant.net/pipermail/edugain-discuss/>
- List-id: "An open discussion list for topics related to the eduGAIN interfederation service." <edugain-discuss.geant.net>
Hello, I noticed that 108 SAML entities in eduGAIN MDS metadata have the hide-from-discovery entity category set. I checked what kind of IdPs have this attribute set and it turns out that most of these IdPs have entityIDs looking like https://idp-test.xx or https://idp-dev.xx. I therefore suppose they are not production IdPs. I can also suppose that some of these IdPs allow login with test accounts. I don't like the idea of eduGAIN metadata including non production SAML entities, especially IdPs, because it brings a risk of user impersonation for all production SPs. It sounds strange to mix test IdPs with production IdPs while we all talk LoA and try to convince institutions they should improve their identity management processes :-\ Since these IdPs are flagged as "hide-from-discovery" in eduGAIN metadata, I am able to filter them out, but 1) "hide-from-discovery" does not mean "test SAML entity", given the spec <https://refeds.org/category/hide-from-discovery/> and 2) it moves the filtering burden to downstream eduGAIN metadata processing, whereas it could be done by the registering federation. Actually why do federation include such test IdPs in their eduGAIN upstream metadata? Are their real use cases? Any chance these test IdPs would be removed from upstream eduGAIN metadata? Regards. --
|
- [eduGAIN-discuss] Test/dev IdPs in eduGAIN metadata, Olivier Salaün, 04/16/2015
- Re: [eduGAIN-discuss] Test/dev IdPs in eduGAIN metadata, Tom Scavo, 16-Apr-2015
- Re: [eduGAIN-discuss] Test/dev IdPs in eduGAIN metadata, Olivier Salaün, 16-Apr-2015
- Re: [eduGAIN-discuss] Test/dev IdPs in eduGAIN metadata, Tom Scavo, 16-Apr-2015
- Re: [eduGAIN-discuss] Test/dev IdPs in eduGAIN metadata, Olivier Salaün, 16-Apr-2015
- Re: [eduGAIN-discuss] Test/dev IdPs in eduGAIN metadata, Nicole Harris, 16-Apr-2015
- Re: [eduGAIN-discuss] Test/dev IdPs in eduGAIN metadata, Peter Schober, 16-Apr-2015
- Re: [eduGAIN-discuss] Test/dev IdPs in eduGAIN metadata, Peter Schober, 16-Apr-2015
- Re: [eduGAIN-discuss] Test/dev IdPs in eduGAIN metadata, Ian Young, 16-Apr-2015
- Re: [eduGAIN-discuss] Test/dev IdPs in eduGAIN metadata, Kristof Bajnok, 17-Apr-2015
- Re: [eduGAIN-discuss] Test/dev IdPs in eduGAIN metadata, Tomasz Wolniewicz, 17-Apr-2015
- Re: [eduGAIN-discuss] Test/dev IdPs in eduGAIN metadata, Peter Schober, 17-Apr-2015
- Re: [eduGAIN-discuss] Test/dev IdPs in eduGAIN metadata, Tom Scavo, 16-Apr-2015
Archive powered by MHonArc 2.6.19.