Skip to Content.
Sympa Menu

shibboleth-dev - RE: [Shib-Dev] FW: [REDCap] E-Signature and Shibboleth

Subject: Shibboleth Developers

List archive

RE: [Shib-Dev] FW: [REDCap] E-Signature and Shibboleth


Chronological Thread 
  • From: "Scott Cantor" <>
  • To: <>
  • Subject: RE: [Shib-Dev] FW: [REDCap] E-Signature and Shibboleth
  • Date: Mon, 27 Sep 2010 12:20:18 -0400
  • Organization: The Ohio State University

> What I am hearing is... "technically, yes. But practically, no."

What's the question? Validating passwords is not the job of the IdP, it's
the job of the authentication service(s) the IdP is using. If that's the use
case, it's not a SAML or IdP issue.

But you asked about forced authentication, and the answer is technically and
practically yes, if the SP does so properly and if the IdP is deployed to
support SAML 2 features like that. Lots of IdPs can do that. It's only a
problem when you get into more exotic deployments that punt to external SSO,
and even then it's sometimes possible.

-- Scott





Archive powered by MHonArc 2.6.16.

Top of Page