Using Different SecurityPolicy for different SP's?
Zmuda, Matthew R
Matthew.R.Zmuda at td.com
Mon Dec 17 13:28:17 EST 2012
Is it possible to use different SecurityPolicy for different SP's?
My current IDP relying-party.xml has 1 SP setup which follows standard AuthNRequest and AuthNRessponse model (IE SP sends me AuthNRequest and I authenticate then create AuthnResponse).
I would like to add another SP, which will use Unsolicited SSO.
What I have noticed is that when I come in on the /profile/SAML2/Unsolicited/SSO URL, Shibboleth creates an AuthNRequest (don't completely understand why?).
This request does not have Message Authentication and it is not signed. These goes against my current Security policy and fails so I never get to the point where I authenticate user and create a response.
I don't see any config that hooks the SecurityPolicy to the RP configuration.
I am using External AuthN for both cases if that makes a difference.
Thanks,
NOTICE: Confidential message which may be privileged. Unauthorized use/disclosure prohibited. If received in error, please go to www.td.com/legal for instructions.
AVIS : Message confidentiel dont le contenu peut être privilégié. Utilisation/divulgation interdites sans permission. Si reçu par erreur, prière d'aller au www.td.com/francais/avis_juridique pour des instructions.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20121217/a4daa376/attachment.html
More information about the users
mailing list