How to retrieve SP required attributes at the IDP before authentication

Cantor, Scott cantor.2 at osu.edu
Wed Mar 21 16:19:00 GMT 2012


On 3/21/12 11:47 AM, "Dierick Bart" <bart.dierick at hotmail.com> wrote:
>After 
>a lot of research I realised that it must be possible to provide the
>required 
>attributes at the authentication request.

If you define an extension and convince everybody to support it.
Otherwise, no.

>They 
>suggest that the required attributes can be setted in the metadata OR in
>the 
>authentication request.

They are wrong, there is no extension in SAML that permits the latter.

>I was already able to put these attributes in the the metadata. But isn't
>it
>better to get these attributes in the authentication request? And by
>value 
>instead of by reference?

Not particularly, unless you think the request would be constantly
changing based on factors that an SP would know about.

-- Scott




More information about the dev mailing list