Artifact metadata resolution in java OpenSAML and FU question on using the MDQ

Cantor, Scott cantor.2 at osu.edu
Wed Oct 11 10:07:39 EDT 2017


On 10/11/17, 6:51 AM, "dev on behalf of Rod Widdowson" <dev-bounces at shibboleth.net on behalf of rdw at steadingsoftware.com> wrote:

> The follow up question is whether, for the purposes of any of our code targeting the MDQ protocol (and here I really mean the
> SP), do we care about the small subset of SAML1 artifacts which don't use the SHA1 of the entityID (and thus are consumable by
> the MDQ). I think that these are just SAML1Artifacts of type 2 and SAML1Artifacts with a <SourceID> inside them.

My recollection is that when the MDQ drafts were done, we just explicitly ruled that possibility out of scope. In theory obviously an MDQ service could consume the SourceID or the endpoint URL from a type 2 directly and do something with it but I think we weren't too concerned about that case, or we were finessing it behind the SHA-1 thing.

Even SAML 2 artifacts are not *required* to use the hash as the SourceID. And the SP doesn't have any way to know whether it was or not at the time it makes the request. I might argue we should change how this is characterized in the draft but we did use the {SHA1} tag for this, which is a little odd. Ian might care to comment. 

-- Scott




More information about the dev mailing list