Question on response status codes on auth failure

Cantor, Scott cantor.2 at osu.edu
Mon Jun 22 10:55:19 EDT 2015


> Why is it so?

I spent less time thinking about it than I have writing this response.

> The major status code seems to propose that there is an error on behalf of
> the requester, which clearly is not the case.

There is no way for the IdP to know in most cases who is at fault, and I didn't analyze every case or create separate mappings for every possible condition.

> Is it safe to reconfigure this, or can this create other problems?

You can do anything you want. Returning any error to an SP is always likely to cause problems.

-- Scott



More information about the users mailing list