shibboleth-dev - Re: SAML Artifact attribute
Subject: Shibboleth Developers
List archive
- From: "Tom Scavo" <>
- To:
- Subject: Re: SAML Artifact attribute
- Date: Mon, 1 May 2006 12:18:29 -0400
- Domainkey-signature: a=rsa-sha1; q=dns; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:to:subject:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; b=RpQ09Vzt/tLmjac1DUfE/3jUfitkBIS2hEcBAG/ihVWj4KJRtn8UquROU3eDSf6gkJ8MvN6FjHNkPAMTMBXh3Rfrkl4sxx+F91lHZJrVsO+sR33z9nqF34lRjx9PgmZusR5CSZsQbRqJ4yOgk1FtQConCm7ijL1juRYO2UykSng=
On 5/1/06, Scott Cantor
<>
wrote:
> We did some informal side-by-side testing of Artifact+push vs.
> POST+query a while back, and found that the Artifact+push case was
> noticeably faster for us. I suppose the amount of improvement probably
> depends on the speed of the machines involved, though.
It mainly depends on how you authenticate the callback and whether you sign
for other uses. With signing, there will be little or no difference, in fact
POST would be faster in most cases, just not by much.
Have you done experiments that suggest this is the case? It would
seem that moving data via the front channel (two hops, with a browser
in the middle) would be more costly in general. Indeed, from the time
the "we're redirecting you" message is displayed in the browser, there
is a one or two second delay before the final redirect. This implies
there is some overhead involved in consuming the assertion at the
browser and/or the assertion consumer service. Maybe most of that is
validating the signature at the ACS, I don't know. In any event, I
don't see how POST can be any better than Artifact even under the best
of circumstances.
Tom
- Re: SAML Artifact attribute, Ian Young, 05/01/2006
- RE: SAML Artifact attribute, Scott Cantor, 05/01/2006
- Re: SAML Artifact attribute, Tom Scavo, 05/01/2006
- RE: SAML Artifact attribute, Scott Cantor, 05/01/2006
- Re: SAML Artifact attribute, Ian Young, 05/02/2006
- Re: SAML Artifact attribute, Tom Scavo, 05/01/2006
- <Possible follow-up(s)>
- Re: SAML Artifact attribute, Tom Scavo, 05/01/2006
- RE: SAML Artifact attribute, Scott Cantor, 05/01/2006
- Re: SAML Artifact attribute, Tom Scavo, 05/01/2006
- RE: SAML Artifact attribute, Scott Cantor, 05/01/2006
- Re: SAML Artifact attribute, Tom Scavo, 05/01/2006
- RE: SAML Artifact attribute, Scott Cantor, 05/01/2006
- RE: SAML Artifact attribute, Scott Cantor, 05/01/2006
Archive powered by MHonArc 2.6.16.