Store IdP in SP session before authentication?
Lukas Hämmerle
lukas.haemmerle at switch.ch
Tue Oct 30 11:48:11 EDT 2018
Dear Shib developers
We noticed a difference in the way Shibboleth and SimpleSAML PHP treat
the scenario where a user wants to log in on an SP, selects IdP A on a
Discovery Service and then returns instead with an assertion from IdP B
to the SP.
* In case of Shibboleth, the SP just accepts this assertion from IdP B
without warning in the logs (as far as I have seen).
* In case of SimpleSAML PHP, the SP rejects the assertion because the
user initially was sent to IdP A but got an assertion from IdP B.
In our case (Shib IdP acting as many virtual IdPs with different
entityIDs), the behaviour of the Shibboleth SP is actually beneficial
because our case and to be honest we were not expecting other SAML
implementations to handle this case differently. However, after
discussing this issue with Jaime (SimpleSAML PHP lead developer) today,
I can also understand the reason why SSP rejects the assertion in this
scenario.
So, maybe Scott as one of the authors of the SAML specification could
shed some light on if the spec says something on this case.
Best Regards
Lukas
--
SWITCH
Lukas Hämmerle, Trust & Identity
GÉANT Project Task Leader of
eduGAIN Service Development - Research and Service Providers
Werdstrasse 2, P.O. Box, 8021 Zurich, Switzerland
phone +41 44 268 15 05, direct +41 44 268 15 64
lukas.haemmerle at switch.ch, http://www.switch.ch
More information about the dev
mailing list