May a shibboleth IdP deliver attributes for authZ without preceding authN ?
Peter Schober
peter.schober at univie.ac.at
Wed Oct 12 11:58:54 BST 2011
* Tom Scavo <trscavo at gmail.com> [2011-10-11 22:38]:
> On Mon, Oct 10, 2011 at 8:14 AM, Markus Ludwig Grandpre
> <markus.grandpre at uni-konstanz.de> wrote:
> >
> > Required attributes are defined in SP's metadata:
> >
> > <AttributeConsumingService index="1">
> > ...
> > </AttributeConsumingService>
>
> In an SPSSODescriptor element? That's not a correct use of that
> element, I'm afraid. That's precisely why a RoleDescriptor of type
> query:AttributeQueryDescriptorType was specified:
Didn't know about that. But how would that change anything for the
OP's (nonsensical, IMHO) request to have the IdP issue an authn
statement (when authn is done elsewhere) over an attribute query?
-peter
More information about the users
mailing list