IDP-initiaded SSO or IdPUnsolicitedSSO

Peter Schober peter.schober at univie.ac.at
Wed Oct 16 05:50:04 EDT 2013


* Jehan Procaccia <Jehan.Procaccia at it-sudparis.eu> [2013-10-16 11:15]:
> org.opensaml.ws.message.decoder.MessageDecodingException: SAML 2
> SPSSODescriptor could not be resolved from metadata for SP entityID:
> https://test.travel.com/TravelSite2/ExternalAuthenticateIMT.jsp

What does the metadata for that SP look like?
(You do have metadata for that SP on record, right?)
If so does it claim SAML2 support e.g. in the
SPSSODescriptor/@protocolSupportEnumeration and
AssertionConsumerService/@Binding attributes?

> Is shibboleth 2.4.0 IDP able to work this way (IDP initiaded) with a
> SAML 1.0 SP ?

No idea, really. SAML2.0 has been around since 2005 (and before that
SAML1.1) and we started with Shibboleth later than that ;)

> then is there a SAML 1.x IDP Unsolicited/SSO config sample ?

I would guess having correct metadata for that SP alone would suffice.

> Do I have to add metadata for that SP in my federation ?

That's not someting anyone can answer. As usual, your /IdP/ needs
metadata for every SP it's meant to interop with. Whether that
metadata is locally managed (e.g. in the IdP's filesystem) or comes
from a trusted third party (a Federation) is irrelevant.
-peter


More information about the users mailing list