Back Channel Communications in shibboleth.

Cantor, Scott cantor.2 at osu.edu
Mon Jun 4 14:44:09 BST 2012


On 6/4/12 6:36 AM, "Peter Schober" <peter.schober at univie.ac.at> wrote:

>* Eddie Harari <eddie.harari at gmail.com> [2012-06-04 12:27]:
>>  can an SP take the SAML2 token comming from the user  agent via IDP
>> and use it as an authentication proof  to a different SP.
>>  Is this a possible scenario ?
>
>See https://wiki.oasis-open.org/security/SAML2DelegationCondition for
>examples and terminology. There might also be material at
>https://spaces.internet2.edu/display/ShibuPortal/Home but I don't know
>the status of that,

That is wordy and overly technical rather than deployer focused, but it's
still accurate. That's the basis of the delegation work we did along with
Unicon and remains the project's implemented solution for what was asked
about.

And no, you can't generally take the original token and do that, SAML
doesn't allow it. You have to exchange it for a new token at the IdP.

-- Scott



More information about the users mailing list