Back Channel Communications in shibboleth.
Cantor, Scott
cantor.2 at osu.edu
Mon Jun 4 14:44:09 BST 2012
On 6/4/12 6:36 AM, "Peter Schober" <peter.schober at univie.ac.at> wrote:
>* Eddie Harari <eddie.harari at gmail.com> [2012-06-04 12:27]:
>> can an SP take the SAML2 token comming from the user agent via IDP
>> and use it as an authentication proof to a different SP.
>> Is this a possible scenario ?
>
>See https://wiki.oasis-open.org/security/SAML2DelegationCondition for
>examples and terminology. There might also be material at
>https://spaces.internet2.edu/display/ShibuPortal/Home but I don't know
>the status of that,
That is wordy and overly technical rather than deployer focused, but it's
still accurate. That's the basis of the delegation work we did along with
Unicon and remains the project's implemented solution for what was asked
about.
And no, you can't generally take the original token and do that, SAML
doesn't allow it. You have to exchange it for a new token at the IdP.
-- Scott
More information about the users
mailing list