signed versus unsigned sp-initiated sso requests

Paul Hethmon paul.hethmon at clareitysecurity.com
Mon Mar 24 17:25:44 EDT 2014


On Mar 24, 2014, at 2:18 PM, Cantor, Scott <cantor.2 at osu.edu<mailto:cantor.2 at osu.edu>> wrote:

Given Shibboleth requires the ACS endpoint in the request match one in
the SP metadata, signing a request does not gain you anything.

Well, the option now exists to not do that if it's signed, so there are
cases where it's useful.

Good to know.

My experience with SP's that implement signed AuthnRequests is 100% failure, even the one's using Shibboleth SP manage to screw it up.

Paul


Paul Hethmon
Chief Software Architect
paul.hethmon at clareitysecurity.com<mailto:paul.hethmon at clareitysecurity.com>


-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140324/f11fea9f/attachment.html 


More information about the users mailing list