ECP Newbie question

Ina Müller ina.mueller at zdv.uni-tuebingen.de
Wed Apr 4 11:57:18 BST 2012


As I understand, an ECP client FIRST asks the user for credentials and 
then afterwards contacts the IdP with these credentials (for example via 
basic auth), is that right?

So if this ECP client (respectively the SP initially contacted by the 
ECP client) is NOT an allowed relying party at our IdP, we can detect 
this illegal access not until our users already gave away their 
credentials, correct?

Or is there any kind of verification between ECP/SP and IdP before the 
user is asked for credentials?

Ina



More information about the users mailing list