Authentication with SAML2 assertion only

Cantor, Scott cantor.2 at osu.edu
Thu Jul 10 17:54:54 EDT 2014


On 7/10/14, 5:50 PM, "Peter Schober" <peter.schober at univie.ac.at> wrote:
>
>Not sure you can have unsolicited responses with ECP, from the top of
>my head. For one I think the IDP would need an endpoint to do
>IDP-initiated ECP, which probably no IDP has.

Strictly speaking, true. So I should amend my answer to say that it
requires spoofing a request from an SP, and yes, that can break some SP
implementations. Doesn't affect mine of course.

-- Scott



More information about the users mailing list