ECP extension needed for active clients

Cantor, Scott cantor.2 at osu.edu
Sun Sep 16 13:28:37 EDT 2012


On 9/16/12 1:22 PM, "Mauro Minella" <Mauro.Minella at microsoft.com> wrote:

> 
>The strange thing, to me, is that after the re-deployment, the log file
>reports
>19:02:37.436 - INFO [Shibboleth-Access:74] -
>20120916T170237Z|87.24.1.141|shibidp.eduteamit.com:443|/profile/SAML2/POST
>/SSO|
>Rather than
>
>18:56:20.874 - INFO [Shibboleth-Access:74] -
>20120916T165620Z|157.56.248.53|shibidp.eduteamit.com:443|/profile/SAML2/SO
>AP/ECP|
>which I receive before my deployment.

That isn't why, you're not even doing ECP here. That's standard SSO via
POST. It can't have changed because of anything you did for ECP since
nothing even used it. Authentication for the POST binding would be handled
however you handled it before.

Perhaps you pointed an ECP client at the wrong endpoint.

-- Scott




More information about the users mailing list