Signing authN requests: yea or nay?

Erdos, Marlena marlena_erdos at harvard.edu
Tue Sep 24 13:34:59 EDT 2013


First off, thank you Scott, Nate, and Tom for responding to my query about
signing authN requests.

What I'm intending to summarize for my colleagues is the following.
Please let me know if I've misinterpreted or missed something major:

Because the IdP will only send back a response to the "right place" for an
SP (i.e. the meta-data-registered ACS endpoint), it doesn't really matter
if  the IdP can't verify that the request actually came from the SP.
That is, only an authorized entity will get a response even if an
unauthorized entity made the request.


**

I absolutely did note the comment on DDS and the info about the ability of
2.4 to allow for bypassing the ACS check.   Very useful info.

My summary above doesn't include that material because I'm going for the
most plain-language and simplest-while-still-correct explanation I can
give.  (Reason: There are clued in folks in my audience but the summary
needs to be understood going forward by people with possibly less
background.)

Thanks!
Marlena



More information about the users mailing list