Shibboleth IDP trust with other IDP

Cantor, Scott cantor.2 at osu.edu
Mon Mar 10 15:53:25 EDT 2014


On 3/10/14, 3:43 PM, "krrishv" <krish.v at gmail.com> wrote:

>If i do something like below it works. I commented the
>urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified from the
>UsernamePassword
>Handler. Now i went and assigned the defaultAuthenticationMethod for SP
>either urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified or
>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport Now it
>redirects to either remote user or usernamepasswd handler. Is that a right
>approach?

I forgot there's a default method declared, so yes, I suppose that works,
but it doesn't really enforce anything. SPs have to enforce their
requirements at their end, they can't leave it to the IdP.

-- Scott




More information about the users mailing list