How to retrieve SP required attributes at the IDP before authentication
Cantor, Scott
cantor.2 at osu.edu
Wed Mar 21 16:19:00 GMT 2012
On 3/21/12 11:47 AM, "Dierick Bart" <bart.dierick at hotmail.com> wrote:
>After
>a lot of research I realised that it must be possible to provide the
>required
>attributes at the authentication request.
If you define an extension and convince everybody to support it.
Otherwise, no.
>They
>suggest that the required attributes can be setted in the metadata OR in
>the
>authentication request.
They are wrong, there is no extension in SAML that permits the latter.
>I was already able to put these attributes in the the metadata. But isn't
>it
>better to get these attributes in the authentication request? And by
>value
>instead of by reference?
Not particularly, unless you think the request would be constantly
changing based on factors that an SP would know about.
-- Scott
More information about the dev
mailing list