IDP-initiaded SSO or IdPUnsolicitedSSO

Peter Schober peter.schober at univie.ac.at
Wed Oct 16 09:54:03 EDT 2013


* Cantor, Scott <cantor.2 at osu.edu> [2013-10-16 15:45]:
> "Unsolicited" responses with SAML 1.1 are triggered with the legacy
> Shibboleth request protocol that dates back to the earliest releases and
> is documented on our Technical Specifications page (the old protocols and
> profiles document).
> 
> Basically the parameters are providerId, shire (the ACS endpoint), and
> target (the SAML 1.1 TARGET).

Since the SP likely won't support attribute queries (and there's no
XMLenc with SAML1) that means the OP wouldn't even need a key, and
more generally the IdP wouldn't even need metadata for this SP --
provided the IDP was configured to interop with anonymous relying
parties using selected profiles?
-peter


More information about the users mailing list