Authentication with SAML2 assertion only

Peter Schober peter.schober at univie.ac.at
Thu Jul 10 18:03:34 EDT 2014


* Cantor, Scott <cantor.2 at osu.edu> [2014-07-10 23:55]:
> On 7/10/14, 5:50 PM, "Peter Schober" <peter.schober at univie.ac.at> wrote:
> >
> >Not sure you can have unsolicited responses with ECP, from the top of
> >my head. For one I think the IDP would need an endpoint to do
> >IDP-initiated ECP, which probably no IDP has.
> 
> Strictly speaking, true. So I should amend my answer to say that it
> requires spoofing a request from an SP, and yes, that can break some SP
> implementations. Doesn't affect mine of course.

Ah, right. So you'd simply do that in your ECP client too.

(Ignoring for the moment what the OP's percieved problem with
SP-initiated is, or how an agent controlling an ECP client would even
know the difference.)
-peter


More information about the users mailing list