OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

saml-dev message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: [saml-dev] Profiles for configuring a web profile SP with multiple IdPs?


On 6/10/14, 2:36 PM, "Will Hartung" <willh@mirthcorp.com> wrote:
>
>I like the discovery profile. It handwaves the actual IdP
>identification process, but it at least abstracts the problem. I think
>we can leverage that using something as simple as an IP range to help
>distinguish the client for our case.

That's usually pretty risky in today's environment but you know your use
case.

> But, most important, it defers
>the decsion outside of the applications, which is important and what I
>was really looking for.

That is the basic intent (also to abstract it from the SAML
implementation).

There are also implementations of that profile from Shibboleth and one
called DiscoJuice in PHP, and the latter supports IP-based geohinting.

Good luck,
-- Scott




[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]