Signing authN requests: yea or nay?

Tom Scavo trscavo at gmail.com
Mon Sep 23 21:30:23 EDT 2013


On Mon, Sep 23, 2013 at 6:51 PM, Erdos, Marlena
<marlena_erdos at harvard.edu> wrote:
>
> Our inclination (as a soon to be live IdP) is to require signed authN
> requests.

Resist the urge to do so :-)

You seem to be deploying a high-maintenance IdP. I mean
"high-maintenance" as in it "requires lots of human hand-holding and
attention." Not sure why you're going down this path when everyone
else in this space is talking about "the API economy" but I'm afraid
your users will not be able to enjoy the full benefits of cross-domain
SSO unless you can loosen things up a little bit. I realize that's not
always possible given organizational constraints, but progress starts
with you, I guess.

Tom


More information about the users mailing list