Authentication with SAML2 assertion only
Peter Schober
peter.schober at univie.ac.at
Thu Jul 10 17:50:28 EDT 2014
* Marek Denis <marek.denis at gmail.com> [2014-07-10 23:40]:
> Taking standard mod_shib+shibd setup into consideration I would like
> to ask *if* there is any posibility for mod_shib to authenticate the
> user if he presents SAML2 authN response only.
> So instead of going to SP first, being redirected to the IdP,
> authenticating myself with the IdP and getting back to the SP with an
> assertion I would get the assertion directly from the IdP and present
> it to the SP?
Works just fine.
> I am almost sure this would not work as-is. Am I right?
Sorry, no, it will. :)
> Also, I am insterested both in ECP and in standard websso
> autentication workflows.
Not sure you can have unsolicited responses with ECP, from the top of
my head. For one I think the IDP would need an endpoint to do
IDP-initiated ECP, which probably no IDP has.
-peter
More information about the users
mailing list