supporting IdP-initiated SSO only

Tom Scavo trscavo at gmail.com
Sat Mar 16 16:08:55 EDT 2013


On Sat, Mar 16, 2013 at 3:48 PM, Ian Young <ian at iay.org.uk> wrote:
>
> The CDS and EDS don't need to see such an IdP at all.

Well, if the metadata spec permitted zero SingleSignOnService
endpoints (as it should), a discovery service would only expose those
IdPs with at least one such endpoint. I doubt the Shib CDS and EDS do
this. They certainly don't have to. The SAML2 spec got it wrong, so
the CDS and EDS can afford to get it wrong as well.

Tom


More information about the dev mailing list