Authentication with SAML2 assertion only
Peter Schober
peter.schober at univie.ac.at
Thu Jul 10 18:03:34 EDT 2014
* Cantor, Scott <cantor.2 at osu.edu> [2014-07-10 23:55]:
> On 7/10/14, 5:50 PM, "Peter Schober" <peter.schober at univie.ac.at> wrote:
> >
> >Not sure you can have unsolicited responses with ECP, from the top of
> >my head. For one I think the IDP would need an endpoint to do
> >IDP-initiated ECP, which probably no IDP has.
>
> Strictly speaking, true. So I should amend my answer to say that it
> requires spoofing a request from an SP, and yes, that can break some SP
> implementations. Doesn't affect mine of course.
Ah, right. So you'd simply do that in your ECP client too.
(Ignoring for the moment what the OP's percieved problem with
SP-initiated is, or how an agent controlling an ECP client would even
know the difference.)
-peter
More information about the users
mailing list