Shibboleth - OAuth SAML Bearer flow
Cantor, Scott
cantor.2 at osu.edu
Fri Apr 3 10:07:03 EDT 2015
On 4/3/15, 7:15 AM, "Jan Du Caju" <Jan.DuCaju at kuleuven.be> wrote:
>Hi,
>
>We successfully configured SAP to work together with our Shibboleth Identity provider for SAP web applications
>Now we would like to implement OAuth SAML Bearer flow for SAP OData services
>Is it possible that our Shibboleth Identity Provider issues SAML bearer assertions for the OAuth SAML bearer flow as the Recipient (SAP Service Provider) of the SAML assertion must be different than the Audience (SAP OData Gateway)
Well a) no, the IdP doesn't support that at the moment, and b) what you just described would be invalid in SAML as a general rule, though that's strictly going by that limited description. It would also be insecure in general to throw bearer assertions around without strictly observed limitations on accepting them.
>or do we have to look towards the ECP profile to implement this
ECP isn't OAuth either, if that's what you're asking.
-- Scott
More information about the users
mailing list