login sequence --shib idp & sp/rp

Ci98yr ci_98yr at yahoo.com
Tue Oct 2 20:12:51 EDT 2012


Thanks again Peter and Scott ; that was very helpful

Sent from my iPhone

On Oct 2, 2012, at 6:13 AM, C G 
wrote:

> Probably this is a basic Q (and for my part did some reading/homework).
> Wanted to confirm if this is a good control flow (among several possible) as per my understanding.
> I am interested in the following scenerio (IDP --> Shib Id provider, SP service provider/RP relying party)
> 
> 0. If user comes directly to IDP, it redirects to SP/RP
> 1. User goes to SP/RP 
> 2. SP/RP sends user to IDP
> 3. IDP asks user to enter _Userid_ and _Password_
> 4. IDP authenticates and asserts via SAML the _Userid_ in step3 
> 5. IDP redirects user back to SP/RP
> 6. SP/RP based on the asserted _Userid_ will open up services
> 
> 
> For the Shib-IDP part, does it set any cookie before redirecting?
> How does SP/RP makes sure that userid that is authenticated is indeed the one to allow access to services?
> specifically how does provision for  man-in-middle attack is addressed? (example flip user-id or stole cookie if there is one)
> 
> many thanks in advance for your pointers 
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20121002/c2ed1a6e/attachment.html 


More information about the users mailing list