supporting IdP-initiated SSO only

Cantor, Scott cantor.2 at osu.edu
Sun Mar 17 15:21:35 EDT 2013


On 3/17/13 3:14 PM, "Tom Scavo" <trscavo at gmail.com> wrote:
>
>>The Shibboleth SP will ignore SAML 2 usage for any IdP without a
>>compatible
>> binding, just like if it was configured to Redirect but the IdP only did
>> POST.
>
>But will the DS?

The DS isn't trying to decide what IdPs to show based on endpoints. It
does a bit of that based on protocol support I think, but not endpoints,
that I can recall anyway.

If you're asking if it will "ignore" and not show IdPs in such a case, I
would think absolutely not, but I haven't looked.

-- Scott




More information about the dev mailing list