shibboleth-dev - RE: [Shib-Dev] idp-initiated SSO
Subject: Shibboleth Developers
List archive
- From: Peter Williams <>
- To: "" <>
- Subject: RE: [Shib-Dev] idp-initiated SSO
- Date: Tue, 7 Oct 2008 09:38:05 -0700
- Accept-language: en-US
- Acceptlanguage: en-US
This is all very nice.
But, is there support for
http://docs.oasis-open.org/security/saml/Post2.0/sstc-saml-tech-overview-2.0-cd-02.html#5.1.4.IdP-Initiated%20SSO:%20%20POST%20Binding|outline
It's not a "third-party" who initiates, in the documented use case. Its
specifically the IDP, one of the two parties in the conversation.
The obvious intent is that the semantics are identical with (or at least
equivalent to) SAML1.1
-----Original Message-----
From: Scott Cantor
[mailto:]
Sent: Tuesday, October 07, 2008 9:34 AM
To:
Subject: RE: [Shib-Dev] idp-initiated SSO
> That's an interesting question. I don't how you could tell a 3rd-party
> initiated request from an SP-initiated one, at the IdP, unless you
> required signed requests (which we don't).
Well, we don't by default, that's up to the deployer. But the answer is, I
proposed an extension for either unsigned or signed requests that
distinguishes them, and makes it possible to make the mechanics all work
without violating the profile.
Sometimes it takes people a while to figure out why I propose things. ;-)
-- Scott
- idp-initiated SSO, yangling_1985, 10/06/2008
- Re: [Shib-Dev] idp-initiated SSO, Chad La Joie, 10/06/2008
- Re: [Shib-Dev] idp-initiated SSO, Nate Klingenstein, 10/06/2008
- RE: [Shib-Dev] idp-initiated SSO, Jeff.Krug, 10/07/2008
- Re: [Shib-Dev] idp-initiated SSO, Chad La Joie, 10/07/2008
- RE: [Shib-Dev] idp-initiated SSO, Scott Cantor, 10/07/2008
- RE: [Shib-Dev] idp-initiated SSO, Peter Williams, 10/07/2008
- RE: [Shib-Dev] idp-initiated SSO, Scott Cantor, 10/07/2008
- RE: [Shib-Dev] idp-initiated SSO, Peter Williams, 10/07/2008
- RE: [Shib-Dev] idp-initiated SSO, Scott Cantor, 10/07/2008
- RE: [Shib-Dev] idp-initiated SSO, Scott Cantor, 10/07/2008
- RE: [Shib-Dev] idp-initiated SSO, Jeff.Krug, 10/07/2008
- RE: [Shib-Dev] idp-initiated SSO, Scott Cantor, 10/07/2008
- Message not available
- RE: [Shib-Dev] idp-initiated SSO, Scott Cantor, 10/07/2008
- RE: [Shib-Dev] idp-initiated SSO, Peter Williams, 10/07/2008
- RE: [Shib-Dev] idp-initiated SSO, Scott Cantor, 10/07/2008
- RE: [Shib-Dev] idp-initiated SSO, Scott Cantor, 10/07/2008
- RE: [Shib-Dev] idp-initiated SSO, Peter Williams, 10/17/2008
- RE: [Shib-Dev] idp-initiated SSO, Scott Cantor, 10/17/2008
- RE: [Shib-Dev] idp-initiated SSO, Peter Williams, 10/17/2008
- RE: [Shib-Dev] idp-initiated SSO, Scott Cantor, 10/17/2008
- RE: [Shib-Dev] idp-initiated SSO, Jeff.Krug, 10/07/2008
- Re: [Shib-Dev] idp-initiated SSO, Chad La Joie, 10/07/2008
- RE: [Shib-Dev] idp-initiated SSO, Jeff.Krug, 10/07/2008
Archive powered by MHonArc 2.6.16.