Skip to Content.
Sympa Menu

participants-research - Re: IdP discovery - list 'em all?

Subject: InC Research Participants

List archive

Re: IdP discovery - list 'em all?


Chronological Thread 
  • From: "Basney, Jim" <>
  • To: "" <>
  • Subject: Re: IdP discovery - list 'em all?
  • Date: Thu, 1 Sep 2016 19:26:35 +0000
  • Accept-language: en-US
  • Ironport-phdr: 9a23:nxOetBXM55c6UaOCwsZHieFvzxbV8LGtZVwlr6E/grcLSJyIuqrYZhWBt8tkgFKBZ4jH8fUM07OQ6P+wHzFbqs/c+Fk5M7VyFDY9wf0MmAIhBMPXQWbaF9XNKxIAIcJZSVV+9Gu6O0UGUOz3ZlnVv2HgpWVKQka3ZkJJIbG/AofIk8W81vi7/YHIJh9Fnze0e7hyBBSwpgLUs84Qx4x4Jex5ngPAuGdJcOVOzGV0PheJkg3x7927/LZi9S9Xvvcm8YhHS6qsLIoiSrkNRh4vKGY49YmjlxjGB0Pb5HEVSWMbgzJJBwzE6hb7RdH8vjas5bk14zWTIcCjFeN8Yj+l9ao+EBI=

On 9/1/16, 12:23 PM, Cantor, Scott wrote:
>The page there says "The R&S and Sirtfi prerequisites are in place to
>satisfy IGTF traceability and uniqueness requirements.", and I was
>curious why that applies only to eduGAIN and not InCommon IdPs.

My summary of the IGTF consensus is that 1) the eduGAIN agreements are
weaker than the InCommon Participation Agreement and 2) eduGAIN IdPs are
"more distant" in terms of dealing with security incidents (e.g., we might
need to involve operators of multiple federations), and (self-asserted)
R&S and Sirtfi compliance provides a compensating control for the added
risks of #1 and #2.

>Maybe related to my question above. I noticed the same disconnect, but it
>sounds like there's a policy reason you can't let them succeed anyway, so
>it's more a case of error behavior. I would agree that it seems confusing
>to hide those IdPs in a way that doesn't clarify to the user what's going
>on.
>
>In that vein, maybe it makes more sense, if you're going to whitelist on
>the basis of an attribute on-boarding process, to still give people the
>chance to select a non-boarded IdP and then simply say "not boarded, this
>is what's got to happen first..."

Yes, it seems I still need to break the IdP-whitelisting habit and instead
focus on better error handling.

Thanks,
Jim




Archive powered by MHonArc 2.6.19.

Top of Page