Metadata question for Embedded Discovery and SP authentication of IdP

Cantor, Scott E. cantor.2 at osu.edu
Wed Aug 3 01:11:53 BST 2011


On 8/2/11 7:11 PM, "Jason Bau" <jasonbau at gmail.com> wrote:

>A follow-up question here.  Won't the SP use the InCommon metadata for
>the IdP
>to authenticate the assertion?  I assume it will do the lookup in the
>metatdata based on urn:mace:incommon:stanford.edu, and the cert for
>the IdP is there under this name.  What is
>missing for this lookup (and thus the SP's authorization of the IdP) to
>fail?

But that wasn't the issuer name in the assertion you got, it was the
Stanford name. Based on the error anyway.

-- Scott



More information about the users mailing list