Lukas, I'm sure the SSP developers (aehm, let's stick with plural for
politeness reasons ;)) are well aware of the situation.
* Lukas Hämmerle <
lukas.h...@switch.ch> [2016-06-22 10:15]:
> Can SSP as of today release attributes based on a SAML2 Entity Category
> (like the REFEDS Research & Scholarship or GÉANT Data Protection Code of
> Conduct entity categories) at all or at least using some plugin/extension?
AFAIK SSP supports the release of attributes based on
RequestedAttribute elements. I'm not aware how to make that release
conditional to e.g. the CoCo category entity attribute of the SP.
With the future amendment to R&S it gets worse as RequestedAttributes
then may not be available in the SP's metadata, which is why I
recently suggested creating an extension to metarefresh that would
decorate R&S SPs with the R&S attribute bundle attributes so that
RequestedAttribute elements would effectively be minted from the
entity attribute, allowing the existing mechanism to continue to work
fine.
Outside of what's included by default, Georg G. has created
https://github.com/gollmann/MetaMerge to help his IDP deal with
eduID.at and eduGAIN metadata, but I have not looked at that in any
detail. It would probably also need updating in light of the amended
R&S spec, I'd imagine.
> * If this is not supported, what is the reason this feature has not been
> added yet and when will it be supported?
The usual? Resources? Changed realities (R&S) not bringing matching
code with them?
> Given that quite a few IdPs use SSP and given that entity
> categor-based attribute release currently seems to be a key success
> factor to battle the attribute release problems in various
> federation (and eduGAIN), I would wonder why this feature is not
> part of SSP.
Pull requests always welcome! :)
Note that there was a huge contribution from Brook a while ago, adding
a quite complex policy language to SSP, but AFAIR that never made it
through code review (still done by Olav, back then). There should be
an open issue about that in Github in case you're interested.
-peter