Forced Authn and IdPUnsolicitedSSO

Cantor, Scott cantor.2 at osu.edu
Mon Aug 4 20:22:01 EDT 2014


On 8/4/14, 8:08 PM, "Tom Scavo" <trscavo at gmail.com> wrote:
>
>I'll add my two cents...it's much easier to "spoof a request" as Scott
>calls it. Just send an AuthnRequest to the IdP as though it had come
>from the DataPower itself. That may sound easier than it actually is
>but implementing a new handler to accomplish this at the IdP is
>certainly much more difficult.

It's about the same, actually. And the latter has the advantage that there
won't be an InResponseTo populated in the response, which could easily
break something broken enough to not support SAML properly in the first
place.

-- Scott



More information about the users mailing list