Understanding flow / federation
Peter Schober
peter.schober at univie.ac.at
Mon Sep 24 06:20:25 EDT 2012
* Bo Lorentsen <bl at moch.dk> [2012-09-24 12:02]:
> On 2012-09-24 10:32, Peter Schober wrote:
> > Individual SAML2 SPs can request specific methods which get mapped
> > to login handlers in handler.xml
>
> And a handler in the idP can decide to let another idP provide the
> auth method (found in the metadata) ?
As I said before:
* Peter Schober <peter.schober at univie.ac.at> [2012-09-18 15:54]:
> So, the IdP only cares about SPs and vice versa.
> There is no IdP to IdP communication, with or without testshib
> involved.
> > You can also add a DefaultRelyingParty/@defaultAuthenticationMethod
> > attribute to your relying-party.xml,
>
> But this is where I end if nothing else is decided, and the SP have
> not provided any info on which method to use ?
Cf. the second sentence in the section "Authentication Method Selection"
on the page https://wiki.shibboleth.net/confluence/display/SHIB2/IdPUserAuthn
-peter
More information about the users
mailing list