signed versus unsigned sp-initiated sso requests
Paul Hethmon
paul.hethmon at clareitysecurity.com
Mon Mar 24 17:25:44 EDT 2014
On Mar 24, 2014, at 2:18 PM, Cantor, Scott <cantor.2 at osu.edu<mailto:cantor.2 at osu.edu>> wrote:
Given Shibboleth requires the ACS endpoint in the request match one in
the SP metadata, signing a request does not gain you anything.
Well, the option now exists to not do that if it's signed, so there are
cases where it's useful.
Good to know.
My experience with SP's that implement signed AuthnRequests is 100% failure, even the one's using Shibboleth SP manage to screw it up.
Paul
Paul Hethmon
Chief Software Architect
paul.hethmon at clareitysecurity.com<mailto:paul.hethmon at clareitysecurity.com>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140324/f11fea9f/attachment.html
More information about the users
mailing list