gpt4 book ai didi

java - SP元数据: physical addresses in attributes entityID and Location

转载 作者:太空宇宙 更新时间:2023-11-04 14:43:18 25 4
gpt4 key购买 nike

the documentation about entity naming表示最好使用域名作为属性 entityID 的值:

Strongly recommended NOT to use the physical hostname of a server running Shibboleth as the entityID. As time passes, things get moved and that deployment may not always live on the same box.

Additionally there may be multiple logical deployments of Shibboleth on a single physical server, each requiring their own unique entityID, so using the server's name doesn't scale beyond a single one.

还有更多:

Some Shibboleth federations have strict policies governing the selection of an entityID, though this is more common with IdPs than SPs. In other federations, selection is up to the federation participant, but operators may enforce basic conventions or react negatively to obviously poor choices. In general, you should check with the federation(s) you plan to join, and follow the advice above.

说明规范:

Metadata for the OASIS Security Assertion Markup Language (SAML)V2.0

entityID [Required] -

 Specifies the unique identifier of the SAML entity whose metadata is 
described by the element's contents.

我的SP部署在沙箱中,没有域名。我可以在属性 entityIDLocation 中使用物理地址(和端口)吗?

最佳答案

由于开发阶段,沙盒部署是可以的,应该没有问题,但完全不适合生产。如文档中所述,在您的场景中,每次更改沙箱 SP 物理位置时,您都必须更新 SP 端和可能的 IdP 端的元数据。

关于java - SP元数据: physical addresses in attributes entityID and Location,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/24721381/

25 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com