clarification of unsolicited SSO behavior

Tom Scavo trscavo at gmail.com
Mon Aug 12 07:56:39 EDT 2013


Hi,

The documentation on unsolicited SSO [1] doesn't say how the IdP
chooses an endpoint location from SP metadata if one is missing in the
protocol message. Of the outbound bindings supported at the IdP, which
takes precedence? Also, if the SP supports multiple endpoints for a
given binding, which one does the IdP choose?

Thanks,

Tom

[1] https://wiki.shibboleth.net/confluence/x/UwBR


More information about the users mailing list