Shibboleth 2.4.3 SP, Oracle Identity Federation 11g IDP SAML1.1 and TARGET
Nicholas Irving
nirving at darkedges.com
Wed Oct 5 05:19:21 BST 2011
Afternoon,
Have an interesting problem. Have Oracle Identity Federation 11g as my IDP
with Shibboleth 2.4.3 SP to use SAML 1.1. I have managed to find all the
necessary metadata changes required to do the integration and it works, if
and only if I manually insert a TARGET value to the POST data via Firefox
and Tamper Data.
After being redirected from the SP to the IDP and I successfully
authenticate, the IDP generates the SAML Assertion and posts to
https://id.xxxxx.com:8443/Shibboleth.sso/SAML/POST?TARGET=%2Fsecure%2F
As you can see the request contains the TARGET parameter, but as part of the
URL and not the POST. So the question is, is this Shibboleth being true to
the SAML 1.1 spec and requiring TARGET to be POST'd or has it missed a trick
and this is a valid request?
I know I can use SAML 2, but I have a requirement to test against a SAML 1.1
SP and so I took this opportunity to learn how to deploy and configure
Shibboleth.
Regards
--
Nicholas Irving
Simple, Accurate, Secure.
04 0007 0562
http://www.darkedges.com/ <http://www.darkedges.com/?gmail>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20111005/60eb9782/attachment.html
More information about the users
mailing list