IDP-initiaded SSO or IdPUnsolicitedSSO

Cantor, Scott cantor.2 at osu.edu
Wed Oct 16 09:57:02 EDT 2013


On 10/16/13 9:54 AM, "Peter Schober" <peter.schober at univie.ac.at> wrote:
>
>Since the SP likely won't support attribute queries (and there's no
>XMLenc with SAML1) that means the OP wouldn't even need a key, and
>more generally the IdP wouldn't even need metadata for this SP --
>provided the IDP was configured to interop with anonymous relying
>parties using selected profiles?

If it's configured that way. Normally you need metadata for the endpoint
check, same as with any use of SAML 2 without encryption.

And yes, you'd have to push attributes which isn't the default for that
profile.

-- Scott




More information about the users mailing list