mace-opensaml-users - [OpenSAML] SAML Profile question
Subject: OpenSAML user discussion
List archive
- From: Chris Card <>
- To: <>
- Subject: [OpenSAML] SAML Profile question
- Date: Thu, 26 Aug 2010 10:21:01 +0000
- Importance: Normal
Hi, [this isn't specifically an opensaml question, but one on the SAML Profiles spec - apologies if there's a better place to ask it] I'm looking at sections 4.1.3.4 Identity Provider Identifies Principal and 4.1.3.5 Identify Provider Issues <Response> to Service Provider, of the SAML Profiles 2.0 spec. In 4.1.3.4 it says: At any time during the previous step or subsequent to it, the identity provider MUST establish the identity In 4.1.3.5 it says: Regardless of the success or failure of the <AuthnRequest>, the identity provider SHOULD produce anWhat happens if the user fails the authentication step (e.g. enter the wrong password)? Does that count as failure of the <AuthnRequest>, so that some kind of <Response> should be delivered back to the SP? Or should the IDP return an error to the SP? If the latter, how should the error be delivered to the SP? Chris |
- RE: [OpenSAML] Signature validation, (continued)
- RE: [OpenSAML] Signature validation, Chris Card, 08/18/2010
- RE: [OpenSAML] Signature validation, Scott Cantor, 08/18/2010
- RE: [OpenSAML] Signature validation, Chris Card, 08/18/2010
- RE: [OpenSAML] Signature validation, Scott Cantor, 08/18/2010
- RE: [OpenSAML] Signature validation, Chris Card, 08/19/2010
- RE: [OpenSAML] Signature validation, Scott Cantor, 08/18/2010
- RE: [OpenSAML] Signature validation, Scott Cantor, 08/18/2010
- RE: [OpenSAML] Signature validation, Chris Card, 08/18/2010
- RE: [OpenSAML] Signature validation, Chris Card, 08/19/2010
- RE: [OpenSAML] Signature validation, Scott Cantor, 08/19/2010
- [OpenSAML] SAML Profile question, Chris Card, 08/26/2010
- RE: [OpenSAML] SAML Profile question, Scott Cantor, 08/26/2010
- RE: [OpenSAML] SAML Profile question, Chris Card, 08/26/2010
Archive powered by MHonArc 2.6.16.