supporting IdP-initiated SSO only
Ian Young
ian at iay.org.uk
Sat Mar 16 15:48:03 EDT 2013
On 16 Mar 2013, at 19:06, Ian Young <ian at iay.org.uk> wrote:
> Not only would the Shibboleth CDS, EDS and SP need to understand such a role descriptor, but every other SP implementation would need to understand it as well, *and* everyone in the world would have to deploy updated software, or such an IdP would just not be visible to them at all.
Actually, that's wrong. The CDS and EDS don't need to see such an IdP at all. It's "just" every SP that the IdP sends unsolicited responses to which would need to understand the new role descriptor, so that they know how to validate the signature on the response. Still a non-starter, I think, but we might as well be accurate about why.
-- Ian
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 4813 bytes
Desc: not available
Url : http://shibboleth.net/pipermail/dev/attachments/20130316/e3aa9147/attachment.bin
More information about the dev
mailing list