On 11 May 2007, at 15:53, Karsten Huneycutt wrote:
> Along those same lines, why can't the IdP Discovery Service
> (optionally) return (signed) metadata about the requested IdP? How
> does the IdP Discovery Service allow a SP to deal with
> participating in multiple federations simultaneously? The service
> will redirect back to the SP, which will allow the SP to redirect
> to other IdP disco services, but
Gah, editing malfunction. To complete my thought:
The service will redirect back to the SP, which will allow the SP to
redirect to other IdP disco services, but what does the user
interface look like for that? Will the first IdP disco service have
a "none of these, sorry!" button? Will the user be presented with
potentially three or four different "choose one of these completely
irrelevant choices" pages before getting to one that has the correct
choice?
KH
--
Karsten Huneycutt
Systems Specialist, ITS Identity Management