Metadata question for Embedded Discovery and SP authentication of IdP
Jason Bau
jasonbau at gmail.com
Wed Aug 3 01:29:57 BST 2011
On Tue, Aug 2, 2011 at 5:11 PM, Cantor, Scott E. <cantor.2 at osu.edu> wrote:
> On 8/2/11 7:11 PM, "Jason Bau" <jasonbau at gmail.com> wrote:
>
>>A follow-up question here. Won't the SP use the InCommon metadata for
>>the IdP
>>to authenticate the assertion? I assume it will do the lookup in the
>>metatdata based on urn:mace:incommon:stanford.edu, and the cert for
>>the IdP is there under this name. What is
>>missing for this lookup (and thus the SP's authorization of the IdP) to
>>fail?
>
> But that wasn't the issuer name in the assertion you got, it was the
> Stanford name. Based on the error anyway.
>
Right, but I was looking for the string "https://idp.stanford.edu" on
the wire but only saw
base64(urn:mace:incommon:stanford.edu). So I was wondering where the
"https://idp.stanford.edu"
identifier was inserted. It must be in the IdP's response to the SP,
but I did not see these bit, so to speak.
Forgive my laziness, but can you point to the doc for these message
formats? I could not find
enough detail in the Wiki.
Jason
> -- Scott
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>
More information about the users
mailing list