1 / 5

Addressing Cross-Federation Practices in SAML Federations

This document outlines the challenges and solutions encountered in implementing cross-federation practices within SAML federations. Key issues include support limitations for SAML2, the prevalence of SAML1.x Identity Providers (IdPs), and the complexities of authorization and adding new IdPs. Discussions focus on metadata encryption, authorization controls, and potential agreements for federation collaboration. It aims to enhance interoperability and trust among federations, highlighting the importance of addressing technical and administrative hurdles.

olinda
Télécharger la présentation

Addressing Cross-Federation Practices in SAML Federations

An Image/Link below is provided (as is) to download presentation Download Policy: Content on the Website is provided to you AS IS for your information and personal use and may not be sold / licensed / shared on other websites without getting consent from its author. Content is provided to you AS IS for your information and personal use only. Download presentation by click this link. While downloading, if for some reason you are not able to download a presentation, the publisher may have deleted the file from their server. During download, if you can't get a presentation, the file might be deleted by the publisher.

E N D

Presentation Transcript


  1. REFEDs WikiA test-bed for cross-federation practices ? <LOCATION TITLE><City, Country><Date> Firstname LastnameJob titlelastname@terena.orgwww.terena.org

  2. Habemus ‘federated’ wiki • We thought we were set…but quiet a few issues arose: • Support for SAML2 only • It turns out that there more SAML1.x IdPs than we thought. • AuthZ, the famous entitlement; • Adding new IdPs, there is something to say about this; • Metadata encryption, hopefully solved. <lastname@terena.org>

  3. Authorisation now • Already in place in the REFEDs wiki operated by RedIRIS:

  4. Authorisation in the future • ACLs? • Using rev. on both sides ?

  5. Adding new IdPs • Several options: • In some cases we simply add the metadata of a specific IdP; • Some federations require the federation IdP to be connected: • TERENA should sign an agreement with that federations; • Some federations proposed TERENA to join that specific federation

More Related