rejecting IdP-initiated responses

Tom Scavo trscavo at gmail.com
Sat Apr 14 22:52:36 BST 2012


On Sat, Apr 14, 2012 at 5:06 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> On 4/14/12 7:56 AM, "Tom Scavo" <trscavo at gmail.com> wrote:
>
>>I have a SAML2-only SP. I want to configure this SP so that it will
>>NOT accept IdP-initiated responses. How do I do that with the Shib SP?
>
> It isn't possible to do that.

I assume you mean that the SP does not support it. Can this feature be
added? It seems to protect against a stolen or otherwise exposed
signing key at the IdP.

Tom


More information about the users mailing list