Metadata question for Embedded Discovery and SP authentication of IdP

Jason Bau jasonbau at gmail.com
Wed Aug 3 01:29:57 BST 2011


On Tue, Aug 2, 2011 at 5:11 PM, Cantor, Scott E. <cantor.2 at osu.edu> wrote:
> On 8/2/11 7:11 PM, "Jason Bau" <jasonbau at gmail.com> wrote:
>
>>A follow-up question here.  Won't the SP use the InCommon metadata for
>>the IdP
>>to authenticate the assertion?  I assume it will do the lookup in the
>>metatdata based on urn:mace:incommon:stanford.edu, and the cert for
>>the IdP is there under this name.  What is
>>missing for this lookup (and thus the SP's authorization of the IdP) to
>>fail?
>
> But that wasn't the issuer name in the assertion you got, it was the
> Stanford name. Based on the error anyway.
>

Right, but I was looking for the string "https://idp.stanford.edu" on
the wire but only saw
base64(urn:mace:incommon:stanford.edu).  So I was wondering where the
"https://idp.stanford.edu"
identifier was inserted.  It must be in the IdP's response to the SP,
but I did not see these bit, so to speak.

Forgive my laziness, but can you point to the doc for these message
formats?  I could not find
enough detail in the Wiki.

Jason

> -- Scott
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>


More information about the users mailing list