supporting IdP-initiated SSO only

Tom Scavo trscavo at gmail.com
Sat Mar 16 16:03:33 EDT 2013


On Sat, Mar 16, 2013 at 3:06 PM, Ian Young <ian at iay.org.uk> wrote:
>
> It sounds like your use case could be described as wanting to make the new IdP less discoverable.

No, that's not what I said (and I didn't mean to imply that). I'm
questioning the metadata spec's requirement that every IdP MUST
support the AuthnRequest protocol.

> I'd think it would be extremely unlikely that approaching this use case by defining a new role descriptor would be practical.  Not only would the Shibboleth CDS, EDS and SP need to understand such a role descriptor, but every other SP implementation would need to understand it as well, *and* everyone in the world would have to deploy updated software, or such an IdP would just not be visible to them at all.  I think that's a non-starter, I'm afraid.

I totally agree, and hence the SAML2 spec gets this wrong.

Tom


More information about the dev mailing list