Shib SP ECP - a few woes

Cantor, Scott cantor.2 at osu.edu
Sat Oct 19 14:45:21 EDT 2013


On 10/18/13 10:06 PM, "Giovanni Bajo" <rasky at develer.com> wrote:
>
>Why signing doesn't fix this?

Because the field the client uses to know where to return the response is
not signed. If it were, the client would have to be able to verify XML
signatures, and that's not a requirement of ECP.

>I guess that also assumes that the IdP will return, in its response to
>the AuthnRequest, the consumer URL extracted from its registered SP
>metadata rather than whatever URL was sent to it in the AuthnRequest.

By definition.

>On a different topic: I can't find a mapping between the ProviderID in
>IdpEntry and what URL the AuthnRequest must be sent to;

That's not in scope of the profile.

> in ecp.py, it is an out-of-band information that is stored in a
>configuration dictionary at the beginning of the file. That sounds
>strange, given that a browser (non-ECP) client doesn't need this
>out-of-band information, since SP will redirect it to the correct URL for
>authentication.

It isn't a redirect.

-- Scott




More information about the users mailing list