SP unsolicited login security
Cantor, Scott
cantor.2 at osu.edu
Thu Aug 25 19:53:26 BST 2011
On 8/25/11 2:20 PM, "Russell Beall" <beall at usc.edu> wrote:
>
>What is the best way to ensure that an SP registered in a federation will
>only accept logins from a particular list of IdP entityIDs?
Whitelist those entityIDs in a metadata filter.
>Is there a way that I can prevent it from allowing Unsolicited logins and
>use only the form-based login requests? (for instance, some setting to
>require that the IdP send an "InResponseTo" value that matches an
>AuthnRequest the SP actually made).
No, not at the moment. The SP doesn't remember its requests.
-- Scott
More information about the users
mailing list