signed versus unsigned sp-initiated sso requests

Cantor, Scott cantor.2 at osu.edu
Mon Mar 24 17:18:34 EDT 2014


On 3/24/14, 5:14 PM, "Paul Hethmon" <paul.hethmon at clareitysecurity.com>
wrote:
>
>Given Shibboleth requires the ACS endpoint in the request match one in
>the SP metadata, signing a request does not gain you anything.

Well, the option now exists to not do that if it's signed, so there are
cases where it's useful.

-- Scott




More information about the users mailing list