Skip to Content.
Sympa Menu

shibboleth-dev - RE: [Shib-Dev] Implementing SLO and help on finding out authenitcated service providers

Subject: Shibboleth Developers

List archive

RE: [Shib-Dev] Implementing SLO and help on finding out authenitcated service providers


Chronological Thread 
  • From: "Scott Cantor" <>
  • To: <>
  • Subject: RE: [Shib-Dev] Implementing SLO and help on finding out authenitcated service providers
  • Date: Tue, 14 Jul 2009 10:19:54 -0400
  • Organization: The Ohio State University

Adam Lantos wrote on 2009-07-14:
> - HTTP connection using SSL with certificate validation from
> metadata. Client authentication will also be required, but since SP is
> behind a web server, it cannot force transport authentication, so
> request signing is a must.

There's nominally support in the SP for allowing it to be configured behind a
dedicated SOAP port that would have client authentication enabled. But I
don't think it actually can get access to the certificate on all of the
platforms. So yes, signing is pretty much the only option.

-- Scott





Archive powered by MHonArc 2.6.16.

Top of Page