RemoteUser login handler using urn:oasis:names:tc:SAML:2.0:ac:classes:Password

Cantor, Scott cantor.2 at osu.edu
Fri Aug 2 13:42:46 EDT 2013


On 8/2/13 1:25 PM, "Kasa, Nubli" <mmohdkas at iu.edu> wrote:

>Hi Colleagues,
> 
>   We have a third party vendor that requires
>urn:oasis:names:tc:SAML:2.0:ac:classes:Password AuthenticationMethod. Is
>it possible to have RemoteUser login handler support
>urn:oasis:names:tc:SAML:2.0:ac:classes:Password?

You can make it "support" anything, but you can't make it return anything
but a single value, which then breaks if one SP wants A and another wants
B, both mapped to one handler. I covered this on the list recently.

You should tell your vendor to quit it. There is almost no chance they
"require" anything, they just don't know how to make requests properly.

Consider if you deploy multi-factor. They're going to tell you that they
won't accept that? Very unliklely. And do you want to be in a situation
where you can't deploy something because it will break a vendor's already
broken system?

-- Scott




More information about the users mailing list