supporting IdP-initiated SSO only

Ian Young ian at iay.org.uk
Sat Mar 16 13:59:44 EDT 2013


On 16 Mar 2013, at 16:57, Tom Scavo <trscavo at gmail.com> wrote:

> I thought I knew the answer to this question but now I'm not so sure...
> 
> Suppose a Shib IdP supports SAML2 IdP-initiated SSO only. What does
> its metadata look like?

Kind of an interesting hypothetical.  Can you explain why a Shib IdP would choose to only support IdP-initiated SAML 2.0 SSO?  That would mean it didn't support the SAML 2.0 Web Browser SSO Profile.  Unsolicited responses are only an optional part of that profile.

> Since an IDPSSODescriptor MUST include at least one
> SingleSignOnService endpoint,

This is related to the fact that the Web Browser SSO Profile in the SAML 2.0 specification involves the SP sending a request to the IdP.

> I'm not sure how to answer that
> question. Seems the only option is to define a custom RoleDescriptor.

If you define a custom RoleDescriptor, no SP will understand it.

	-- Ian



-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 4813 bytes
Desc: not available
Url : http://shibboleth.net/pipermail/dev/attachments/20130316/42d1fd6e/attachment.bin 


More information about the dev mailing list