Advice on planned IdP configuration changes associated with implementing SAML 2

Tom Scavo trscavo at gmail.com
Fri Sep 13 09:20:07 EDT 2013


On Fri, Sep 13, 2013 at 4:27 AM, Julian Williams
<julian.williams at it.ox.ac.uk> wrote:
> On 11/09/13 16:01, Cantor, Scott wrote:
>>
>> What I did, which may not apply to the UK, is to manipulate my InCommon
>> metadata to include a SAML 2 ArtifactResolutionService only, which causes
>> (in the InCommon case) my IdP metadata to include the necessary SAML 2
>> protocol support string, but with no SSO endpoint. That allowed me to push
>> transactions to an SP using the IdP's unsolicited SSO endpoint and probe
>> for problems ahead of time, before users are impacted. This was with the
>> same IdP users use, and doesn't require SP changes.
>
> That's interesting and sounds very useful if we could do it. I'll have
> to check with the UK Federation but I suspect it will be to late for
> this time around. When you say "push transactions to an SP using the
> IdP's unsolicited SSO endpoint" can you give me an example of how this
> is done?

Shib documentation for IdP unsolicited SSO:
https://wiki.shibboleth.net/confluence/x/UwBR

InCommon documentation for the technique Scott mentioned:
https://spaces.internet2.edu/x/YpmKAQ

HTH,

Tom


More information about the users mailing list