[JIRA] Updated: (IDP-84) Allow signed requests to bypass ACS verification

Chad La Joie (JIRA) noreply at shibboleth.net
Fri Sep 9 14:19:26 BST 2011


     [ https://issues.shibboleth.net/jira/browse/IDP-84?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Chad La Joie updated IDP-84:
----------------------------

    Component/s: Security and Cryptography
                 SAML2

> Allow signed requests to bypass ACS verification
> ------------------------------------------------
>
>                 Key: IDP-84
>                 URL: https://issues.shibboleth.net/jira/browse/IDP-84
>             Project: Identity Provider
>          Issue Type: Improvement
>          Components: SAML2, Security and Cryptography
>            Reporter: Scott Cantor
>            Assignee: Chad La Joie
>            Priority: Minor
>
> A lot of implementations apparently assume that if you have a signed AuthnRequest, that takes the place of checking the ACS location, which makes a lot of sense to me, and would offer some real benefits. Suggest we expose an option to bypass checking if the request is authenticated. 

--
This message is automatically generated by JIRA.
For more information on JIRA, see: http://www.atlassian.com/software/jira


More information about the commits mailing list