funny AssertionConsumerService URL

Martin Haase Martin.Haase at DAASI.de
Thu Feb 13 11:50:57 EST 2014


Hi,
maybe I'm naive, but I always thought it is the ServerName directive
that determines the SP's ACS URL when UseCanonicalName is On. By
bugtracking this afternoon on some customer site, I learned that the
target parameter dictates it as well. Might be sensible for other vhosts
on the same box, but why does something like
https://mysp.example.de/Shibboleth.sso/Login?target=http://www.google.de
create, in the SAML Request, an ACS URL of
http://www.google.de/Shibboleth.sso/SAML2/POST? Just asking...The IdP
turns it down of course, but I had expected the real ACS URL in the
request, and the SP redirecting to Google after AuthN.
Cheers,
Martin


-- 
Dr. Martin Haase, Solutions Engineer

DAASI International GmbH        
Europaplatz 3                   
D-72072 Tübingen                
Germany                    

phone: +49 7071 407109-6
fax:   +49 7071 407109-9  
email: martin.haase at daasi.de
web:   www.daasi.de

Sitz der Gesellschaft: Tübingen
Registergericht: Amtsgericht Stuttgart, HRB 382175
Geschäftsleitung: Peter Gietz


-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 2345 bytes
Desc: S/MIME Cryptographic Signature
Url : http://shibboleth.net/pipermail/users/attachments/20140213/d88610b2/attachment-0001.bin 


More information about the users mailing list