Skip to Content.
Sympa Menu

technical-discuss - Re: [InC-Technical] Fwd: who needs support for ECP?

Subject: InCommon Technical Discussions

List archive

Re: [InC-Technical] Fwd: who needs support for ECP?


Chronological Thread 
  • From: Scott Koranda <>
  • To: "Farmer, Jacob" <>
  • Cc: Nick Roy <>, "" <>
  • Subject: Re: [InC-Technical] Fwd: who needs support for ECP?
  • Date: Thu, 7 Sep 2017 16:43:32 -0500
  • Ironport-phdr: 9a23:Rb4R2hMIjee6u4QH//Al6mtUPXoX/o7sNwtQ0KIMzox0I/n6rarrMEGX3/hxlliBBdydsKMUzbKO+4nbGkU4qa6bt34DdJEeHzQksu4x2zIaPcieFEfgJ+TrZSFpVO5LVVti4m3peRMNQJW2aFLduGC94iAPERvjKwV1Ov71GonPhMiryuy+4ZPebgFLiTanfb9+MAi9oBnMuMURnYZsMLs6xAHTontPdeRWxGdoKkyWkh3h+Mq+/4Nt/jpJtf45+MFOTav1f6IjTbxFFzsmKHw65NfqtRbYUwSC4GYXX3gMnRpJBwjF6wz6Xov0vyDnuOdxxDWWMMvrRr0vRz+s87lkRwPpiCcfNj427mfXitBrjKlGpB6tvgFzz5LIbI2QMvd1Y6HTcs4ARWdZUMhfVzJPDJ6/YYsBAOUOIftXoYb/qFQAtha+GQqhCfnzxjNUnHL6wKs32PkhHwHc2wwgGsoDvmnIo9XyKKcSTf2+wqzPzTXZdfxW3yry55LVeR0muvGMXrVwcdDLxkkpCgzKlE6dqYPgPzyP1+QNt3KX4PZnVeKqkmMqrRx6rDaoxscpkIbJh4QVx0jK9SV4xYY4Kse4RFR8Yd6+H5tcry6aN4pqQsMiXmFnozw2yrwBuZKjYScF0o4oxwXea/CdboeH/BTuX/uSLzdgnH9pZrOyiwqw/EWlxO3xVdK73EpPoydKjtXAqm0C2hnP5cSbTvZw+0Ks1SiR2w/O8u1IPE45mKvBJ5I8w7M9lIAfvErCEyPshkn6kq2be0M58eay8evneK/pppqEOo90lA7+NqMul9S6AesiMwgOW3GX+f2/1LH/5EH4T6tGguMrnaXDv5DaIsMbpqG9AwBLyIos9xG/DzK+3NQZm3kIMk5FdQqZg4XoJ13DIvX1Dfm8jlu3jDtmwv/LMqH9DprQK3XMjKvtcLJ45kNZ1gY/081Q64pRCr4bIfLzXkHxtMbfDh88KwG02OXnCNJn1owEX2KAH7WWPbjdsV+N/O0vIu2MaJUJtzb6Lvgp/+TugmMhmV8BYamp2oMaaHG+Hvt6JEWZZH/sgtAHEWsQuQo+VuPqhESeUTFNe3myX6Q85jAnB428CYfPX52igL2a3CinA51WfXtGB0uIEXfpbIWER+wMZDyILs9glDwESaauS5Un1R6wqA/21aBrIfTJ9S0F5trf040/yeTJkBwosXRWBs+a2SvFG2NskGoSQjIs9KFi50Fx1wHQ/7J/hqljHttP+7tqVR0zM5LVh7hhCNfoUwTNd/+GTV+nRpOtBjRnHYF5+MMHf0soQ4bqtRvExSf/RuZNz7E=

Hi,

I would argue that everybody that thinks they want to input into the
FIM4R discussion of ECP should join the FIM4R email list and directly
contribute.

See

https://fim4r.org/

and click 'Contact'.

Thanks,

Scott K

> Nick,
>
> Could you create something like a Google form for people to report their
> usage?
> That might facilitate a large volume of responses.
>
> Jacob
>
> On Sep 7, 2017, at 5:33 PM, Nick Roy
> <>
> wrote:
>
>
> FYI - it would be good to understand the use of ECP in InCommon. How
> many
> of you use/need ECP? It is included as a MUST for IdPs in the Kantara
> SAMLv2.0 Implementation Profile for Federation Interoperability:
> https://
> kantarainitiative.github.io/SAMLprofiles/fedinterop.html It is possible
> that could change if few real use cases exist.
>
> Best,
>
> Nick
>
>
> -------- Forwarded Message --------
> Subject: who needs support for ECP?
> Resent-From:
>
> Date: Thu, 7 Sep 2017 20:43:53 +0200
> From: Peter
> <>
> To:
>
> CC:
>
>
>
>
> Dear FIM4R people,
>
> within AARC2 a very lively and sophisticated discussion has taken place
> about the question whether SAML ECP should be mandatory or not in a SAML
> idP software
> conformance document.
>
> Although the main use case of ECP (non-web SSO) can be handled by other
> technologies such as OAuth2/OIDC, a number of SAML based deployments
> need ECP. The question is, how high this number is, and the idea came up
> to ask this list, which I am doing herewith:
>
> Who of you think that a proper SAML IdP-Implementation should support
> ECP and who uses it within their research infrastructure.
>
> To start answering the question:
>
> In DARIAH we have specified and implemented a Storage API that uses ECP
> for authentication. A second version of this API also supports OAuth2,
> thus although we would not need ECP support any more I still think that
> a SAML document should mandate ECP so that named use cases could be
> implemented within one technology stack such as SAML. There might be
> security considerations though that speak against ECP.
>
> So now its your turn to answer the question ;-)
>
> Cheers
>
> Peter
>
>
> --
> _______________________________________________________________________
>
> Peter Gietz (CEO)
> DAASI International GmbH phone: +49 7071 407109-0
> Europaplatz 3 Fax: +49 7071 407109-9
> D-72072 Tübingen mail:
>
> Germany Web: www.daasi.de
>
> DAASI International GmbH, Tübingen
> Geschäftsführer Peter Gietz, Amtsgericht Stuttgart HRB 382175
>
> Directory Applications for Advanced Security and Information Management
> _______________________________________________________________________
>
>
>
> To unsubscribe from this list, send email to
>
> with the
> subject: unsubscribe technical-discuss
>

> To unsubscribe from this list, send email to
>
> with the subject: unsubscribe technical-discuss




Archive powered by MHonArc 2.6.19.

Top of Page