Shibboleth IDP trust with other IDP
Cantor, Scott
cantor.2 at osu.edu
Mon Mar 10 15:53:25 EDT 2014
On 3/10/14, 3:43 PM, "krrishv" <krish.v at gmail.com> wrote:
>If i do something like below it works. I commented the
>urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified from the
>UsernamePassword
>Handler. Now i went and assigned the defaultAuthenticationMethod for SP
>either urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified or
>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport Now it
>redirects to either remote user or usernamepasswd handler. Is that a right
>approach?
I forgot there's a default method declared, so yes, I suppose that works,
but it doesn't really enforce anything. SPs have to enforce their
requirements at their end, they can't leave it to the IdP.
-- Scott
More information about the users
mailing list