Authentication with SAML2 assertion only

Peter Schober peter.schober at univie.ac.at
Thu Jul 10 17:50:28 EDT 2014


* Marek Denis <marek.denis at gmail.com> [2014-07-10 23:40]:
> Taking standard mod_shib+shibd  setup into consideration I would like
> to ask *if* there is any posibility for mod_shib to authenticate the
> user if he presents SAML2 authN response only.
> So instead of going to SP first, being redirected to the IdP,
> authenticating myself with the IdP and getting back to the SP with an
> assertion I would get the assertion directly from the IdP and present
> it to the SP?

Works just fine.

> I am almost sure this would not work as-is. Am I right?

Sorry, no, it will. :)

> Also, I am insterested both in ECP and in standard websso
> autentication workflows.

Not sure you can have unsolicited responses with ECP, from the top of
my head. For one I think the IDP would need an endpoint to do
IDP-initiated ECP, which probably no IDP has.
-peter


More information about the users mailing list