rejecting IdP-initiated responses
Tom Scavo
trscavo at gmail.com
Sat Apr 14 22:52:36 BST 2012
On Sat, Apr 14, 2012 at 5:06 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> On 4/14/12 7:56 AM, "Tom Scavo" <trscavo at gmail.com> wrote:
>
>>I have a SAML2-only SP. I want to configure this SP so that it will
>>NOT accept IdP-initiated responses. How do I do that with the Shib SP?
>
> It isn't possible to do that.
I assume you mean that the SP does not support it. Can this feature be
added? It seems to protect against a stolen or otherwise exposed
signing key at the IdP.
Tom
More information about the users
mailing list