Shibboleth 2.4.3 SP, Oracle Identity Federation 11g IDP SAML1.1 and TARGET

Chad La Joie lajoie at itumi.biz
Wed Oct 5 05:43:30 BST 2011


Shibboleth is not generating that URL, the IdP is.  And in the POST
binding the target is a form parameter.  So your IdP isn't an SAML 1.1
IdP (meaning it does not following the SAML specification).

On Wed, Oct 5, 2011 at 00:19, Nicholas Irving <nirving at darkedges.com> wrote:
>
> Afternoon,
> Have an interesting problem. Have Oracle Identity Federation 11g as my IDP with Shibboleth 2.4.3 SP to use SAML 1.1. I have managed to find all the necessary metadata changes required to do the integration and it works, if and only if I manually insert a TARGET value to the POST data via Firefox and Tamper Data.
>
> After being redirected from the SP to the IDP and I successfully authenticate, the IDP generates the SAML Assertion and posts to
> https://id.xxxxx.com:8443/Shibboleth.sso/SAML/POST?TARGET=%2Fsecure%2F
>
> As you can see the request contains the TARGET parameter, but as part of the URL and not the POST. So the question is, is this Shibboleth being true to the SAML 1.1 spec and requiring TARGET to be POST'd or has it missed a trick and this is a valid request?
>
> I know I can use SAML 2, but I have a requirement to test against a SAML 1.1 SP and so I took this opportunity to learn how to deploy and configure Shibboleth.
>
> Regards
> --
> Nicholas Irving
> Simple, Accurate, Secure.
> 04 0007 0562
> http://www.darkedges.com/
>
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net



--
Chad La Joie
www.itumi.biz
trusted identities, delivered


More information about the users mailing list