Skip to Content.

edugain-discuss - Re: [eduGAIN-discuss] Support for WS Federation protocol in edugain

edugain-discuss AT lists.geant.org

Subject: An open discussion list for topics related to the eduGAIN interfederation service.

List archive


Re: [eduGAIN-discuss] Support for WS Federation protocol in edugain


Chronological Thread 
  • From: Peter Schober <peter.schober AT univie.ac.at>
  • To: edugain-discuss AT lists.geant.org
  • Subject: Re: [eduGAIN-discuss] Support for WS Federation protocol in edugain
  • Date: Fri, 15 May 2020 13:49:50 +0200
  • Organization: ACOnet

* Daniel Muscat <daniel.muscat AT um.edu.mt> [2020-05-15 13:25]:
> If I have an IDP supporting the WS Federation Protocol how do I
> publish it?

Well, that's a question you'd have to answer when/before registering
such an IDP within *your* local federation, before it ever makes it to
eduGAIN, no?
(Only stuff from local federations ever makes it to the eduGAIN MDS.)

So by definition this is not question of "eduGAIN supporting" this or
not.

> Is there a way how to specify that this WSFed based and not
> SAML/shibboleth based?

eduGAIN -- as well as many academic large-scale multi-party
federations (outside HPC/Grid) -- is currently based on the exchange
of SAML 2.0 Metadata.
So if whatver you need can be expressed in SAML 2.0 Metadata -- and
the products expected to use that information can consume it from
there -- you're done: You put it into SAML 2.0 Metadata.

If OTOH the information needed to communicate between WS-Fed systems
*cannot* be expressed by SAML 2.0 Metadata you'd have to tell us what
that alternative means of communication is, exactly, and then we can
discuss whether to make "eduGAIN support" it.[1]

-peter

[1] Not that I personally would support such a hypothetical change
proposal that would only benefit a few M$ implementations.



Archive powered by MHonArc 2.6.19.

Top of Page