ECP working

Cantor, Scott cantor.2 at osu.edu
Tue Jun 3 09:52:51 EDT 2014


On 6/3/14, 3:57 AM, "Lukas Haemmerle" <lukas.haemmerle at switch.ch> wrote:
>
>Does this mean that the client (script) has to send the "Authorization:
>Basic QWxhZGRpbjpvcGVuIHNlc2FtZQ==" header already with the first
>request without getting a HTTP 401 from the server?

Yes. I haven't found a way to render a SWF or MVC "view" that does nothing
but send a 401 back.

I may be able to make this work with the new External authn approach I
defined, but I'm not sure why an ECP client in the non-browser case would
ever need to be challenged.

Ultimately part of describing IdPs to ECP clients has to include
authentication interface descriptors to identify the mechanism to be used.

-- Scott




More information about the dev mailing list