Understanding flow / federation

Peter Schober peter.schober at univie.ac.at
Mon Sep 24 06:20:25 EDT 2012


* Bo Lorentsen <bl at moch.dk> [2012-09-24 12:02]:
> On 2012-09-24 10:32, Peter Schober wrote:
> > Individual SAML2 SPs can request specific methods which get mapped
> > to login handlers in handler.xml
>
> And a handler in the idP can decide to let another idP provide the
> auth method (found in the metadata) ?

As I said before:

  * Peter Schober <peter.schober at univie.ac.at> [2012-09-18 15:54]:
  > So, the IdP only cares about SPs and vice versa.
  > There is no IdP to IdP communication, with or without testshib
  > involved.

> > You can also add a DefaultRelyingParty/@defaultAuthenticationMethod
> > attribute to your relying-party.xml,
>
> But this is where I end if nothing else is decided, and the SP have
> not provided any info on which method to use ?

Cf. the second sentence in the section "Authentication Method Selection"
on the page https://wiki.shibboleth.net/confluence/display/SHIB2/IdPUserAuthn
-peter


More information about the users mailing list