Question regarding configuration of shibboleth using NativeSPBackDoor

Cantor, Scott cantor.2 at osu.edu
Wed Jun 27 21:38:42 BST 2012


On 6/27/12 4:29 PM, "Chu, Man Sin" <ManSin.Chu at alliancebernstein.com>
wrote:
>
>Sorry for not explaining clearly.  I have installed shibboleth service
>provider 2.4.3 and the isapi is up and running on iis.  I am able to get
>to the status page.  So installation with default configuration is
>working.  I am not sure how to configure it as one way authentication
>where the idp sent us the request and does not expect us to send them
>back a handshake.

I don't know what handshake you're referring to. The SP handles
IdP-initiated SSO without any special work. There is no "handshake" in
SAML. The message to the SP is a response and completes the exchange. If
there's no request from the SP to start with, that's the part that's
missing, not the end.

>That seem to me is a one way authentication.  That is why I thought
>nativespbackdoor is the correct way.  Obviously I am so wrong about that

You may want to read up on SAML SSO profile behavior. You may also find
the material in the wiki on "Understanding Shibboleth" helpful.

-- Scott



More information about the users mailing list