Shib SP ECP - a few woes
Cantor, Scott
cantor.2 at osu.edu
Sat Oct 19 14:45:21 EDT 2013
On 10/18/13 10:06 PM, "Giovanni Bajo" <rasky at develer.com> wrote:
>
>Why signing doesn't fix this?
Because the field the client uses to know where to return the response is
not signed. If it were, the client would have to be able to verify XML
signatures, and that's not a requirement of ECP.
>I guess that also assumes that the IdP will return, in its response to
>the AuthnRequest, the consumer URL extracted from its registered SP
>metadata rather than whatever URL was sent to it in the AuthnRequest.
By definition.
>On a different topic: I can't find a mapping between the ProviderID in
>IdpEntry and what URL the AuthnRequest must be sent to;
That's not in scope of the profile.
> in ecp.py, it is an out-of-band information that is stored in a
>configuration dictionary at the beginning of the file. That sounds
>strange, given that a browser (non-ECP) client doesn't need this
>out-of-band information, since SP will redirect it to the correct URL for
>authentication.
It isn't a redirect.
-- Scott
More information about the users
mailing list