...
It is important that the implementation and deployment of all InCommon services facilitate their initial on-boarding processes to avoid operational and technical impediments to adoption, as described in Recommended Practices for InCommon Participants.
More specifically, R&S services generally have a broad user community, often including people who do not have a close relationship with the Service Provider, nor do those people's IdPs. For this reason, R&S Service Providers are encouraged to consider the following guidelines:
- The service should not require out-of-band negotiation with IdPs.
- The service should request a subset of R&S Category Attributes, and furthermore, the service should request only those attributes it absolutely needs. (See the section on R&S Category Attributes for details.)
- The SP should fully support SAML V2.0 Web Browser SSO (see the the SP Endpoints in Metadata wiki page).
- The SP should provide a complete set of of User Interface Elements in metadata. In particular, a Privacy Statement and a Logo are highly recommended.
- In addition to the Technical and Administrative contacts Administrative Contacts in metadataMetadata required of all SPs, a Security contact should also be provided (once that option becomes available).
- The SP should strive to provide a good, overall user experience Federation User Experience. In particular, the SP should should intelligently handle errors involving the release of requested attributes.
...