Signed AuthnRequest

Brent Putman putmanb at georgetown.edu
Thu Mar 20 13:26:11 EDT 2014


On 3/20/14 10:23 AM, Cantor, Scott wrote:
> On 3/20/14, 8:03 AM, "Vasu Y" <vyal2k at yahoo.com> wrote:
>
> I don't think the IdP omits the Destination check based on whether the
> message was signed (though it's of no value in unsigned cases), but
> regardless, you are failing to follow the standard and not setting a
> Destination attribute.

Well, that's literally true, the IdP doesn't *omit* the check based on
signing or not.  Actually, however, it does change its behavior based on
whether the message is signed, per the SAML spec.  If the message is
signed, the Destination attribute is required and checked against the
delivered endpoint.  If the message is not signed then: 1) if
Destination is there it's evaluated (and can fail if doesn't match the
delivered endpoint) 2) if the Destination is not there, it's not an
error, the eval is just skipped.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140320/49c8bce4/attachment.html 


More information about the users mailing list