[JIRA] Updated: (IDP-84) Allow signed requests to bypass ACS verification
Chad La Joie (JIRA)
noreply at shibboleth.net
Fri Sep 9 14:19:26 BST 2011
[ https://issues.shibboleth.net/jira/browse/IDP-84?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Chad La Joie updated IDP-84:
----------------------------
Component/s: Security and Cryptography
SAML2
> Allow signed requests to bypass ACS verification
> ------------------------------------------------
>
> Key: IDP-84
> URL: https://issues.shibboleth.net/jira/browse/IDP-84
> Project: Identity Provider
> Issue Type: Improvement
> Components: SAML2, Security and Cryptography
> Reporter: Scott Cantor
> Assignee: Chad La Joie
> Priority: Minor
>
> A lot of implementations apparently assume that if you have a signed AuthnRequest, that takes the place of checking the ACS location, which makes a lot of sense to me, and would offer some real benefits. Suggest we expose an option to bypass checking if the request is authenticated.
--
This message is automatically generated by JIRA.
For more information on JIRA, see: http://www.atlassian.com/software/jira
More information about the commits
mailing list