SP unsolicited login security

Cantor, Scott cantor.2 at osu.edu
Thu Aug 25 19:53:26 BST 2011


On 8/25/11 2:20 PM, "Russell Beall" <beall at usc.edu> wrote:
>
>What is the best way to ensure that an SP registered in a federation will
>only accept logins from a particular list of IdP entityIDs?

Whitelist those entityIDs in a metadata filter.

>Is there a way that I can prevent it from allowing Unsolicited logins and
>use only the form-based login requests?  (for instance, some setting to
>require that the IdP send an "InResponseTo" value that matches an
>AuthnRequest the SP actually made).

No, not at the moment. The SP doesn't remember its requests.

-- Scott



More information about the users mailing list