26 ms·
Opening that documentation page gave me flashbacks. I made the switch out of IT to another field. Configuring a Shibboleth IdP was probably the hardest thing I
by mjthompson 6y ago
Opening that documentation page gave me flashbacks.
I made the switch out of IT to another field. Configuring a Shibboleth IdP was probably the hardest thing I ever had to do in my IT career, it really pushed my capabilities. SLO wasn't the only hard thing, the whole thing was immensely challenging and every time I'd restart Jetty I'd be holding my breath hoping it would come up again.
- mooreds 6y agoWhat are you doing now?
- mjthompson 6y agoI'm a lawyer. Very different, I know! I love IT and programming, but I knew if I made a life long career of it, I'd grow to hate it. I really like doing IT related things in my own way. I'd always want to do things to best practices and not just get the job done as I was told.
- dkdk8283 6y agoI would love to pivot to law, I helped my ex do a lot of her homework and have a false sense of understanding. Only problem is that I’m old and a new start will not be easy when competing with people 20 years younger.
- mjthompson 6y agoI know solicitors a fair bit older than me (is, in their 40s) who made the jump and find they more readily gain the respect and trust of clients, and senior lawyers within the firm, by virtue of their maturity.
- varikin 6y agoI had just started a new job and my manager handed me a project to implement the SP side of SAML into our monolith. He explicitly said, I looked at the docs and don't want to deal with that headache. Fuck, that was a pain in the ass. So many bugs just due to conflicting statements in different parts of the docs. Everything can be done 5 different ways.
- rcaught 6y agoThe SP is a walk in the park compared to the IdP.
- rkeene2 6y agoTo be fair, SAML itself isn't that difficult -- Shibboleth is just not very good. I implemented a SAML IdP [0] in MUCH less time than it took to configure Shibboleth. The specification for SAML is pretty easy to comprehend. The implementation is really an experiment, but the configuration and usability is significantly better. Improving the implementation doesn't affect this. In some closed-source forks I've written a production version that's been in use for several years. [0] https://github.com/rkeene/saml-idp/blob/master/lib/saml/saml.tcl https://github.com/rkeene/saml-idp/blob/master/lib/saml/saml...
- deleted 6y ago[deleted]
- 35fbe7d3d5b9 6y agoThis is a direct result of a spec that basically says "here's a grab bag of options, pick what suits you". Maybe your IdP expects SOAP over HTTP but your SP won't. Perhaps the SP insists on encrypting AuthnRequests. God help you if one side wants to do URL encoding and DEFLATE. I've made my life easier by refusing to ask/answer questions around SSO and instead insisting on talking about "ADFS login". We still do SAML, but at least there's a baseline implementation that I can plan for.