Authentication with SAML2 assertion only
Cantor, Scott
cantor.2 at osu.edu
Thu Jul 10 17:45:12 EDT 2014
On 7/10/14, 5:39 PM, "Marek Denis" <marek.denis at gmail.com> wrote:
>
>So instead of going to SP first, being redirected to the IdP,
>authenticating myself with the IdP and getting back to the SP with an
>assertion I would get the assertion directly from the IdP and present
>it to the SP?
That's IdP initiated SSO, it's required by the standard that an SP
implementation support it, and this implementation doesn't currently have
a way to disable it.
>I am almost sure this would not work as-is. Am I right?
Nope, it works fine. It's also technically a CSRF attack, unfortunately.
>Also, I am insterested both in ECP and in standard websso
>autentication workflows.
Same; ECP is the same underlying profile with different bindings around it.
-- Scott
More information about the users
mailing list