supporting IdP-initiated SSO only

Peter Williams pwilliams at rapattoni.com
Sat Mar 16 14:49:02 EDT 2013


Once, an Russian military plane went down in flames at a Paris airshow, on almost its first public showing. The official report was "properly written" - and properly reflected the desires of the both  governments. Both wished to keep out of the public eye the  real cause (one spy plane induced the other to counter the spying attempt, killing someone unfortunate enough to be beneath the "game"). Thus, the report used proper double-speak - saying two things at once. No fact was untruthful; but language induced a false reliance to the typical reader. Journalists were properly 'Briefed", and duly typically towed the line (in order to retain access "privileges").

Such is normal in technical/political committees; and reporting. If a standards documents doesn't have politics in it, the committee wasn't doing its job. Such is the case where is HIGHLY ambiguous (probably by design and agreement) that the SAML2  authn protocol does not include idp-initiated. But, also, it does not clearly exclude it the features related to id-initated built into the type system - all of which is good evidence of committee discord, solved "politically".

What is clear is what the [commodity] market wants - which is that matters at nearly 15 years after the websso idea was first formulated (as an inter-domain cookie, in some or other blob format).  What government audited, million dollar deployments for "national infrastructures" want is a different issue, of course. 
 
I just come from the era of 'market always leads'; though I recognize things have shifted back to 1950s-era giant government-managed infrastructure is best, in the last 10 years. In the commodity market, the case for idp-initiated is just OBVIOUS; to the point where benefits of an lack of formal compliance to X is just an "irrelevant" fact - like needing to publicly account for the actual causes of dying at an airshow.








-----Original Message-----
From: dev-bounces at shibboleth.net [mailto:dev-bounces at shibboleth.net] On Behalf Of Ian Young
Sent: Saturday, March 16, 2013 11:34 AM
To: Shib Dev
Subject: Re: supporting IdP-initiated SSO only


On 16 Mar 2013, at 18:22, Tom Scavo <trscavo at gmail.com> wrote:

>> That would mean it didn't support the SAML 2.0 Web Browser SSO Profile.  Unsolicited responses are only an optional part of that profile.
> 
> I don't think unsolicited responses are specified in the SAML 2.0 Web 
> Browser SSO Profile (which is why I sent to the question to this shib 
> list and not the saml-dev list).

Section 4.1.5.

	-- Ian





More information about the dev mailing list