Getting Signed SAML assertion in application

Cantor, Scott cantor.2 at osu.edu
Mon Jan 20 09:29:39 EST 2014


On 1/20/14, 8:32 AM, "Peter Schober" <peter.schober at univie.ac.at> wrote:
>
>Or it just might. Reading the warning section more closely it says
>"the XML is passed along unmodified from the issuer".

It is, the use case was delegation via a signed assertion.

It is almost a given that any "back-end" trying to evaluate a standard SSO
assertion is going to be ignoring the SAML standard in validating it,
unless the back-end is simply acting as an agent of the front-end. Web
service delegation with standard SSO tokens is invalid on its face.

-- Scott




More information about the users mailing list