assurance - Re: [Assurance] questions about how to implement incommon bronze/silver assurance
Subject: Assurance
List archive
Re: [Assurance] questions about how to implement incommon bronze/silver assurance
Chronological Thread
- From: David Walker <>
- To:
- Subject: Re: [Assurance] questions about how to implement incommon bronze/silver assurance
- Date: Tue, 10 Sep 2013 15:07:51 -0700
Welcome! There's a lot involved in being certified for the assurance program, much of which is not technology. Here are some useful references; they're all linked from the InCommon Assurance Program site at http://www.incommon.org/assurance/ .
It may be tempting to read the IAP first, as it contains all of the requirements for Bronze and Silver certification, but read the IAAF first. The IAAF provides context for the IAP and introduces a number of important concepts that can be confusing if you read the IAP first. To answer your specific questions... The IAP describes requirements for how you verify a person's identity, register that person in your IdMS, issue credentials, etc. before they can claim any assurance profile. The IAP also has requirements for how authentication is done for the current session. Typically, completion of the non-authentication requirements for a particular person is stored, as you said, in LDAP or some other data store. The authentication requirements, however, must be satisfied at the time an SP requests an assertion from your IdP. The way this is communicated to an SP is in a SAML assertion, as the result of a SAML request from the SP. Upon receiving a request for a particular assurance profile, the IdP looks up whether the user has met the non-authentication requirements, and then performs any necessary authentication. "Assurance Enhancements for the Shibboleth Identity Provider": https://spaces.internet2.edu/download/attachments/37650957/AssuranceReqShibIdP-19Apr2013.pdf?version=1&modificationDate=1366405685823 describes this process in agonizing detail. David Walker On Tue, 2013-09-10 at 20:34 +0000, XiaoXia Dong wrote: Hello all, |
- [Assurance] questions about how to implement incommon bronze/silver assurance, XiaoXia Dong, 09/10/2013
- Re: [Assurance] questions about how to implement incommon bronze/silver assurance, David Walker, 09/10/2013
- Re: [Assurance] questions about how to implement incommon bronze/silver assurance, Cantor, Scott, 09/10/2013
- Re: [Assurance] questions about how to implement incommon bronze/silver assurance, Ann West, 09/18/2013
- Re: [Assurance] questions about how to implement incommon bronze/silver assurance, Cantor, Scott, 09/18/2013
- RE: [Assurance] questions about how to implement incommon bronze/silver assurance, Dunker, Mary, 09/18/2013
- RE: [Assurance] questions about how to implement incommon bronze/silver assurance, XiaoXia Dong, 09/18/2013
- RE: [Assurance] questions about how to implement incommon bronze/silver assurance, Dunker, Mary, 09/18/2013
- Re: [Assurance] questions about how to implement incommon bronze/silver assurance, Cantor, Scott, 09/18/2013
- Re: [Assurance] questions about how to implement incommon bronze/silver assurance, Ann West, 09/18/2013
Archive powered by MHonArc 2.6.16.