Passthrough of SAML response by SP to application
Dennis Wagelaar
dennis.wagelaar at healthconnect.be
Mon Jul 16 09:13:11 EDT 2012
-----Original Message-----
From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of Dennis Wagelaar
*snip*
-----Original Message-----
From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor, Scott
*snip*
On 7/13/12 8:52 AM, "Dennis Wagelaar" <dennis.wagelaar at healthconnect.be>
wrote:
>Hello all,
>
>Is it possible to have the Shibboleth SP pass through the entire SAML
>response instead of only selected attributes to the underlying web
>application?
Yes, this is documented under assertion export. It's somewhat roundabout because of the size, but it works.
[DW] Thanks! I had already run into size issues with SAML tokens embedded in HTTP headers. This seems to solve that issue. (sorry about my Outlook not properly indenting replies :/)
*snip*
[DW] I've just tried out Assertion Export, but I get a stripped-down SAML response, not the original (see attachment). In particular, all signature information is missing, which is necessary to re-validate the SAML response on the delegated web service (i.e. SP B wants to verify that "user X is authenticated and connected to SP A"). Is there any way to retrieve the cryptographic signature as well?
Thanks!
-- Dennis
-------------- next part --------------
An embedded and charset-unspecified text was scrubbed...
Name: AssertionExport.txt
Url: http://shibboleth.net/pipermail/users/attachments/20120716/7db60eaf/attachment.txt
More information about the users
mailing list