Few questions regarding Shibboleth and SAML

Peter Schober peter.schober at univie.ac.at
Wed Aug 6 11:33:40 EDT 2014


* Moonlight <mona0045 at gmail.com> [2014-08-06 13:05]:
> - How does IdP store the information about earlier successful
> authentication. 

In memory, currently, why do you want to know this?

> - On which endpoint the authorization decision assertion is exchanged.

There is no authorization decision assertion support in the IDP,
AFAIK. The IDP will issue authentication assertions and attribute
assertions.

> - Why it is mentioned in shibboleth wiki that server side code running in a
> web application needs ECP profile.

I doubt that the documentation claims that unconditionally. ECP is for
accessing HTTP-based resources (which are potected with Shib/SAML)
from a user agent which is not an ordinary HTTP user agent.
So if the use case requires it and the IDPs you need to federate with
support it, you can use ECP.
-peter


More information about the users mailing list