login sequence --shib idp & sp/rp
C G
ci_98yr at yahoo.com
Tue Oct 2 07:13:39 EDT 2012
Probably this is a basic Q (and for my part did some reading/homework).
Wanted to confirm if this is a good control flow (among several possible) as per my understanding.
I am interested in the following scenerio (IDP --> Shib Id provider, SP service provider/RP relying party)
0. If user comes directly to IDP, it redirects to SP/RP
1. User goes to SP/RP
2. SP/RP sends user to IDP
3. IDP asks user to enter _Userid_ and _Password_
4. IDP authenticates and asserts via SAML the _Userid_ in step3
5. IDP redirects user back to SP/RP
6. SP/RP based on the asserted _Userid_ will open up services
For the Shib-IDP part, does it set any cookie before redirecting?
How does SP/RP makes sure that userid that is authenticated is indeed the one to allow access to services?
specifically how does provision for man-in-middle attack is addressed? (example flip user-id or stole cookie if there is one)
many thanks in advance for your pointers
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20121002/52c18fab/attachment.html
More information about the users
mailing list