Fail on resolved RequestedAttribute isRequired=true
Stefan Santesson
stefan at aaa-sec.com
Tue Jul 14 09:44:52 EDT 2015
Thanks,
You and Leif have convinced me that I was right.
Case closed.
/Stefan
On 14/07/15 15:06, "users on behalf of Tom Scavo"
<users-bounces at shibboleth.net on behalf of trscavo at gmail.com> wrote:
>On Tue, Jul 14, 2015 at 8:36 AM, Stefan Santesson <stefan at aaa-sec.com>
>wrote:
>>
>> Can you tell the Shib3 IdP to fail authentication if SP metadata lists
>>an
>> attribute as required, but the attribute filter policy does not release
>> that attribute?
>
>An IdP should *never* fail authentication unless there is some aspect
>of the authentication request that it can't satisfy. Whoever tries to
>tell you otherwise just doesn't get it.
>
>> The tests I¹ve done concludes that Shib IdP does not fail auth in this
>> case. It delivers what the filer policy releases, disregarding that it
>> does not match a required attribute in metadata.
>
>That seems perfectly logical to me.
>
>> Personally I think this is OK. Out of the two options, it is better to
>> deliver what you can, rather than to return an error, and let the SP
>> decide whether it wants to fail or not.
>
>Assuming you mean "fail authentication" and "return an error" are the
>same thing, I totally agree.
>
>Spread the faith!
>
>Tom
>--
>To unsubscribe from this list send an email to
>users-unsubscribe at shibboleth.net
More information about the users
mailing list