Authentication with SAML2 assertion only

Cantor, Scott cantor.2 at osu.edu
Thu Jul 10 17:45:12 EDT 2014


On 7/10/14, 5:39 PM, "Marek Denis" <marek.denis at gmail.com> wrote:
>
>So instead of going to SP first, being redirected to the IdP,
>authenticating myself with the IdP and getting back to the SP with an
>assertion I would get the assertion directly from the IdP and present
>it to the SP?

That's IdP initiated SSO, it's required by the standard that an SP
implementation support it, and this implementation doesn't currently have
a way to disable it.

>I am almost sure this would not work as-is. Am I right?

Nope, it works fine. It's also technically a CSRF attack, unfortunately.

>Also, I am insterested both in ECP and in standard websso
>autentication workflows.

Same; ECP is the same underlying profile with different bindings around it.

-- Scott



More information about the users mailing list