Cross-Context External Authn w/ IdP Initiated SSO
snekse
snekse at gmail.com
Fri Jul 25 13:50:15 EDT 2014
Related to the IdP-initiated SSO, should I be able to see the
'/idp/profile/SAML2/Unsolicited/SSO' path in my metadata at
/idp/profile/Metadata/SAML?
Wondering because I'm running into the error
*No profile handler configured for request at path: /SAML2/Unsolicited/SSO*
We're using the shibboleth-identityprovider-2.4.0.jar
This is in my handler.xml:
<ph:ProfileHandler xsi:type="ph:SAML2SSO"
inboundBinding="urn:mace:shibboleth:2.0:profiles:AuthnRequest"
outboundBindingEnumeration="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign
urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST
urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact">
<ph:RequestPath>/SAML2/Unsolicited/SSO</ph:RequestPath>
</ph:ProfileHandler>
On Fri, Jul 25, 2014 at 12:15 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> On 7/25/14, 1:11 PM, "snekse" <snekse at gmail.com> wrote:
> >
> >Your concern about the user bookmarking the SP resource brings me great
> >concern that there's still something I don't get. If I was using the
> >standard SSO protocol, wouldn't I still run into that issue?
>
> It's not your issue (as the IdP), it's the application's issue. If it's
> not solved, it's not solved, but pushing users via a portal doesn't solve
> it, it's just how people pretend it's not a problem.
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140725/4fa57f49/attachment-0001.html
More information about the users
mailing list