Fail on resolved RequestedAttribute isRequired=true
Tom Scavo
trscavo at gmail.com
Tue Jul 14 10:27:43 EDT 2015
On Tue, Jul 14, 2015 at 10:25 AM, Peter Schober
<peter.schober at univie.ac.at> wrote:
> * Stefan Santesson <stefan at aaa-sec.com> [2015-07-14 14:37]:
>> Can you tell the Shib3 IdP to fail authentication if SP metadata
>> lists an attribute as required, but the attribute filter policy does
>> not release that attribute?
>
> There are pathological cases (seemingly becoming more common with SaaS
> vendors) where the SP pushed authorisation to the IDP, i.e., they
> expect you to abort the transaction if the subejct isn't authorized to
> access a given SAML SP (or maybe they charge you per unique subject,
> even if the subject is unauthorized, something along those lines...)
Yes, that's a good point, but that's a completely different use case
that usually (never?) relies on requested attributes in SP metadata.
Tom
More information about the users
mailing list