SP unsolicited login security

Russell Beall beall at usc.edu
Thu Aug 25 19:20:22 BST 2011


I notice that I can log into a sample SP I am toying with using any IdP as long as the SP has its metadata loaded.

What is the best way to ensure that an SP registered in a federation will only accept logins from a particular list of IdP entityIDs?

Is there a way that I can prevent it from allowing Unsolicited logins and use only the form-based login requests?  (for instance, some setting to require that the IdP send an "InResponseTo" value that matches an AuthnRequest the SP actually made).

Thanks,
Russ.



More information about the users mailing list