Shibboleth - OAuth SAML Bearer flow

Cantor, Scott cantor.2 at osu.edu
Fri Apr 3 10:07:03 EDT 2015


On 4/3/15, 7:15 AM, "Jan Du Caju" <Jan.DuCaju at kuleuven.be> wrote:

>Hi,
> 
>We successfully configured SAP to work together with our Shibboleth Identity provider for SAP web applications
>Now we would like to implement OAuth SAML Bearer flow for SAP OData services
>Is it possible that our Shibboleth Identity Provider issues SAML bearer assertions for the OAuth SAML bearer flow as the Recipient (SAP Service Provider) of the SAML assertion must be different than the Audience (SAP OData Gateway)

Well a) no, the IdP doesn't support that at the moment, and b) what you just described would be invalid in SAML as a general rule, though that's strictly going by that limited description. It would also be insecure in general to throw bearer assertions around without strictly observed limitations on accepting them.

>or do we have to look towards the ECP profile to implement this

ECP isn't OAuth either, if that's what you're asking.

-- Scott



More information about the users mailing list