supporting IdP-initiated SSO only
Ian Young
ian at iay.org.uk
Sat Mar 16 13:59:44 EDT 2013
On 16 Mar 2013, at 16:57, Tom Scavo <trscavo at gmail.com> wrote:
> I thought I knew the answer to this question but now I'm not so sure...
>
> Suppose a Shib IdP supports SAML2 IdP-initiated SSO only. What does
> its metadata look like?
Kind of an interesting hypothetical. Can you explain why a Shib IdP would choose to only support IdP-initiated SAML 2.0 SSO? That would mean it didn't support the SAML 2.0 Web Browser SSO Profile. Unsolicited responses are only an optional part of that profile.
> Since an IDPSSODescriptor MUST include at least one
> SingleSignOnService endpoint,
This is related to the fact that the Web Browser SSO Profile in the SAML 2.0 specification involves the SP sending a request to the IdP.
> I'm not sure how to answer that
> question. Seems the only option is to define a custom RoleDescriptor.
If you define a custom RoleDescriptor, no SP will understand it.
-- Ian
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 4813 bytes
Desc: not available
Url : http://shibboleth.net/pipermail/dev/attachments/20130316/42d1fd6e/attachment.bin
More information about the dev
mailing list