Skip to Content.
Sympa Menu

shibboleth-dev - RE: Token passing from SSO

Subject: Shibboleth Developers

List archive

RE: Token passing from SSO


Chronological Thread 
  • From: "Scott Cantor" <>
  • To: <>
  • Cc: "'Nate Klingenstein'" <>, "'Shibboleth Development'" <>
  • Subject: RE: Token passing from SSO
  • Date: Wed, 22 Jun 2005 16:55:46 -0400
  • Organization: The Ohio State University

> I see what you mean. The providerId that gets sent to the IdP is never
> returned to the SP though. Unless it gets put into an
> <Audience>? Or maybeit does - what's your thoughts?

It's in the Audience. It's a SHOULD in the spec, though, admittedly. In 2.0,
it's a MUST.

> The first thing the gateway, as you put it, knows about a Shibboleth
> session is when an AuthenticationStatement from an IdP arrives. The
> gateway didn't initiate this. A guard did that. If the Audience contained
> the Guard's providerId that would solve the problem.

It would if you assign each guard the right providerId when it makes its
AuthnRequest GET.

-- Scott




Archive powered by MHonArc 2.6.16.

Top of Page