Skip to Content.
Sympa Menu

shibboleth-dev - RE: [Shib-Dev] yet another java SP implementation....

Subject: Shibboleth Developers

List archive

RE: [Shib-Dev] yet another java SP implementation....


Chronological Thread 
  • From: "Cantor, Scott E." <>
  • To: "" <>
  • Subject: RE: [Shib-Dev] yet another java SP implementation....
  • Date: Mon, 3 Jan 2011 21:14:53 +0000
  • Accept-language: en-US

> There is? Are you talking about the 3rd-party requester thing?

No, the original SSO profile explicitly requires support for the unsolicited
case. As I said, this is no different than what SAML 1.1 did. Step 1 is
undefined because it was a matter for the IdP deployer, not a wire or
inter-implementation consideration.

To be honest, I'm tired of defending my usual position on it. I'd be inclined
at this point to just take the Shibboleth legacy protocol and use it for both
protocols.

If and when we come up with justifications for signing requests (i.e.,
bypassing ACS checks), it just becomes something that only works in the
SP-initiated case.

-- Scott




Archive powered by MHonArc 2.6.16.

Top of Page