Why is SAML 1 being used instead of SAML 2?
Cantor, Scott
cantor.2 at osu.edu
Tue Apr 14 12:26:24 EDT 2015
On 4/14/15, 12:09 PM, "Kevin Foote" <kpfoote at uoregon.edu> wrote:
>
>> On Apr 14, 2015, at 9:04 AM, Dan Malone <dmalone at calpoly.edu> wrote:
>>
>>We were also given a WAYFless URL, using the InCommon DS:
>> https://wayf.incommonfederation.org/DS/WAYF?shire=https%3A%2F%2Fportfolium.com%2Fsso%2FSAML%2FPOST&target=https%3A%2F%2Fportfolium.com%2Flogin%2Fsso%3Fnetwork_id%3D6%26from%3D&providerId=https%3A%2F%2Fportfolium.com%2Fshibboleth&action=selection&origin=https%3A%2F%2Fidp.calpoly.edu%2Fidp%2Fshibboleth
>
>The URL is telling it to use SAML1 is it not?
It's a Shibboleth authentication request redirect, which is specifically for a SAML 1 response.
That's not a WAYFless URL, that's a request *to* a WAYF using the old protocol.
You can't go through a DS in a way that will work for SAML 2 unless the SP supports the DS protocol (and if it's not Shibboleth or maybe SSP, it doesn't, though it could probably be hacked into supporting it).
-- Scott
More information about the users
mailing list