Skip to Content.
Sympa Menu

assurance - Re: [Assurance] Addressing InCommon IAP & Shibboleth IdP

Subject: Assurance

List archive

Re: [Assurance] Addressing InCommon IAP & Shibboleth IdP


Chronological Thread 
  • From: "Cantor, Scott" <>
  • To: "<>" <>
  • Cc: "" <>, Russell J Yount <>
  • Subject: Re: [Assurance] Addressing InCommon IAP & Shibboleth IdP
  • Date: Wed, 8 Aug 2012 13:27:51 +0000
  • Accept-language: en-US

On Aug 8, 2012, at 8:02 AM, "Russell J Yount" <> wrote:

I could not find references on wiki.shibboleth.net as to how Shibboleth IdP handles sessions with enough details to point an auditor too.


Out of curiosity, is there any product, or indeed web application that does document that in such detail? I ask because it reflects on the wisdom of that level of detail in the document.

How have others addressed this area? Would it make sense for the InCommon Assurance group to put some text together for a stock Shibboleth installation and perhaps for common add-ons such as the Ohio State Custom Login Handler which provides technical details that one could point an auditor to?


What does an auditor require? Is a statement to the truth of the requirement sufficient? And how, again, is anybody running, say, ADFS expected to get their answer?


-- Scott



Archive powered by MHonArc 2.6.16.

Top of Page