Question concerning Authentication Method
Brewer, Edward L
lee.brewer at Vanderbilt.Edu
Tue Jul 8 16:11:52 EDT 2014
Scott,
My confusion lies in the statement where you stated that I need to create a custom login handler. I was under the assumption that the authn engine makes the decision to pass control over to the appropriate login handler. In both cases I have working login handlers. My problem seems to be both are set to PasswordProtectedTransport auth method in the handler.xml. It appears (from my limited knowledge of the code) that authn decides based upon whether the SP signals the auth method, what is in the replying party for the SP, or some default if all else fails. If I were to create new login handler wouldn't it still be (since that is how it works ) a passwordprotectedtransport auth method and I would be back to square one?
I imagine I am missing something here,
Lee Brewer
-----Original Message-----
From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor, Scott
Sent: Tuesday, July 08, 2014 3:00 PM
To: Shib Users
Subject: Re: Question concerning Authentication Method
On 7/8/14, 3:40 PM, "Brewer, Edward L" <lee.brewer at Vanderbilt.Edu> wrote:
>
>If I were to change the External login handler to use
>urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified auth method vice
>PasswordProtectedTransport, then configure the one and only SP that
>needs this login handler (currently) to only use this external login handler...
>could I have some level of success? Also considering that the SP is an
>internal application that I have some level of control over.
The IdP ignores requests for "unspecified" for reasons that are hopefully obvious.
-- Scott
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list