clarification of unsolicited SSO behavior

Tom Scavo trscavo at gmail.com
Mon Aug 12 11:51:42 EDT 2013


On Mon, Aug 12, 2013 at 10:28 AM, Cantor, Scott <cantor.2 at osu.edu> wrote:
>> The documentation on unsolicited SSO [1] doesn't say how the IdP
>> chooses an endpoint location from SP metadata if one is missing in the
>> protocol message.
>
> It picks the default endpoint, per the spec.
>
>> Of the outbound bindings supported at the IdP, which
>> takes precedence?
>
> The binding isn't what determines the default, that's not how metadata defaulting is defined.

Yup, I see all that now, thanks. (Not sure what I was thinking
earlier.) So, for example, since the isDefault XML attribute is not
used in InCommon metadata, the IdP will grab the first endpoint
(smallest index) with a binding it supports. Sound right?

Tom


More information about the users mailing list