shibboleth-dev - RE: [Shib-Dev] Writing an IDP extension
Subject: Shibboleth Developers
List archive
- From: "Scott Cantor" <>
- To: <>
- Subject: RE: [Shib-Dev] Writing an IDP extension
- Date: Tue, 14 Oct 2008 15:37:51 -0400
- Organization: The Ohio State University
> If I the SP send a request with ForceAuth=true, and the IDP sends me back
an
> uncorrelated signed unsolicited response (formally), I really have no
> assurance that the IDP performed the forceAuth requirement.
Yes, you do, you look at the AuthnInstant.
> I cannot decide whether the root cause flaw is in the conformance design
for
> SAML2 or Shib IDP (or the notion that an SP can be entirely stateless).
The SP has nothing to do with it. Requesting forceAuthn and then correlating
a response proves nothing. You know you asked for forceAuthn. That's nice.
Means nothing. The only protection you have is to check the timestamp, which
is what I do (or the app can).
This is *aside* from the fact that any SP worth running is going to accept
unsolicited responses anyway, at which point it has no correlation to
perform and has to check the timestamp anyway.
-- Scott
- Re: [Shib-Dev] Writing an IDP extension, (continued)
- Re: [Shib-Dev] Writing an IDP extension, Chad La Joie, 10/09/2008
- Re: [Shib-Dev] Writing an IDP extension, André Cruz, 10/10/2008
- RE: [Shib-Dev] Writing an IDP extension, Scott Cantor, 10/10/2008
- RE: [Shib-Dev] Writing an IDP extension, Peter Williams, 10/10/2008
- RE: [Shib-Dev] Writing an IDP extension, Scott Cantor, 10/10/2008
- RE: [Shib-Dev] Writing an IDP extension, Peter Williams, 10/10/2008
- RE: [Shib-Dev] Writing an IDP extension, Scott Cantor, 10/10/2008
- RE: [Shib-Dev] Writing an IDP extension, Peter Williams, 10/13/2008
- RE: [Shib-Dev] Writing an IDP extension, Scott Cantor, 10/14/2008
- RE: [Shib-Dev] Writing an IDP extension, Peter Williams, 10/14/2008
- RE: [Shib-Dev] Writing an IDP extension, Scott Cantor, 10/14/2008
- RE: [Shib-Dev] Writing an IDP extension, Scott Cantor, 10/10/2008
- Re: [Shib-Dev] Writing an IDP extension, André Cruz, 10/10/2008
- Re: [Shib-Dev] Writing an IDP extension, Chad La Joie, 10/09/2008
- Re: [Shib-Dev] Writing an IDP extension, Chad La Joie, 10/14/2008
- Re: [Shib-Dev] Writing an IDP extension, André Cruz, 10/15/2008
Archive powered by MHonArc 2.6.16.