Shibboleth and Office365 - Fixes
Peter Schober
peter.schober at univie.ac.at
Mon Jan 28 08:26:20 EST 2013
* Manuel Subredu <manuel.subredu at roedu.net> [2013-01-28 14:12]:
> On 1/28/13 3:05 PM, Peter Schober wrote:
> > * Manuel Subredu <manuel.subredu at roedu.net> [2013-01-28 13:39]:
> > I don't think that's possible (but I have no idea what a "office365
> > log form" is).
>
> http://www.office365.com -> Sign In
That page asks me for a userid and password.
Possible this is being used for IdP discovery *and* local logins at
the same time, with the added "benefit" of your password going to the
first site *and* your own IdP later :(
While a SAML2 Authentication Request can contain a Subject element
(to specify a NameID; you'd have to look at the specs what the
sementics are here) I doubt office365.com implements this.
If it did the IdP could probably get at it via a scripted attr def.
-peter
More information about the users
mailing list