login sequence --shib idp & sp/rp

C G ci_98yr at yahoo.com
Tue Oct 2 07:13:39 EDT 2012


Probably this is a basic Q (and for my part did some reading/homework).
Wanted to confirm if this is a good control flow (among several possible) as per my understanding.
I am interested in the following scenerio (IDP --> Shib Id provider, SP service provider/RP relying party)

0. If user comes directly to IDP, it redirects to SP/RP

1. User goes to SP/RP 
2. SP/RP sends user to IDP
3. IDP asks user to enter _Userid_ and _Password_
4. IDP authenticates and asserts via SAML the _Userid_ in step3 
5. IDP redirects user back to SP/RP
6. SP/RP based on the asserted _Userid_ will open up services


For the Shib-IDP part, does it set any cookie before redirecting?
How does SP/RP makes sure that userid that is authenticated is indeed the one to allow access to services?
specifically how does provision for  man-in-middle attack is addressed? (example flip user-id or stole cookie if there is one)

many thanks in advance for your pointers 
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20121002/52c18fab/attachment.html 


More information about the users mailing list