where is HTTPS/HTTP set for the relying party endpoint return?
Paul Hethmon
paul.hethmon at clareitysecurity.com
Fri Aug 5 19:27:32 BST 2011
No.
If the metadata says HTTP and the request uses an exact match endpoint,
then it will use that. If the metadata says SSL and the request uses an
exact match endpoint, then it will use that.
The metadata for the SP that the IdP has loaded sets the allowable
endpoints to return the response to. For security reasons, the
authentication request must send an exact match to return the response to.
Paul
On 8/5/11 2:20 PM, "Peterson, Tommy" <Tommy.Peterson at xpandcorp.com> wrote:
>So are you saying if the request comes from HTTP it will send it back to
>HTTP. If the request of the IDP comes from HTTPS it will expect to a
>return to HTTPS?
>
>That there is no forced setting?
>
>
>
>-----Original Message-----
>From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net]
>On Behalf Of Cantor, Scott E.
>Sent: Friday, August 05, 2011 2:18 PM
>To: users at shibboleth.net
>Subject: Re: where is HTTPS/HTTP set for the relying party endpoint
>return?
>
>On 8/5/11 2:08 PM, "Peterson, Tommy" <Tommy.Peterson at xpandcorp.com> wrote:
>
>>What determines whether the return endpoint for the SP on the IDP is
>>HTTPS or HTTP?
>
>YOU do. You determine the Apache settings. Not us, and not the SP.
>
>You can't change the metadata and suddenly expect the web site to change
>its spots. You deployed it with http. Changing the metadata has nothing to
>do with changing the web site to use https. The metadata simply describes
>your deployment. It's your deployment that's flawed.
>
>-- Scott
>
>--
>To unsubscribe from this list send an email to
>users-unsubscribe at shibboleth.net
>
>This message contains Devin Group confidential information and is
>intended only for the individual named. If you are not the named
>addressee you should not disseminate, distribute or copy this e-mail.
> Please notify the sender immediately by e-mail if you have received this
>e-mail in error and delete this e-mail from your system. E-mail
>transmissions cannot be guaranteed secure, error-free and information
>could be intercepted, corrupted, lost, destroyed, arrive late,
>incomplete, or contain viruses. The sender therefore does not accept
>liability for errors or omissions in the contents of this message which
>may arise as result of transmission. If verification is required please
>request hard-copy version.
>--
>To unsubscribe from this list send an email to
>users-unsubscribe at shibboleth.net
More information about the users
mailing list