Question on response status codes on auth failure

Stefan Santesson stefan at aaa-sec.com
Tue Jun 23 06:41:33 EDT 2015



On 22/06/15 18:12, "Cantor, Scott" <cantor.2 at osu.edu> wrote:
>
>None of it is hardcoded, the point of that file is to create any mappings
>you want. But since you asked, I would in fact advise that you stop
>caring, this will do nothing significant to improve anybody's experience.
>
>Your focus should really be on preventing the condition from arising.

Of course, except for the two conditions that I have no control over.

1) The user hit the ³cancel button²
2) The user enters wrong credentials/PIN/password or user does not exisit.

It is only these conditions that are of any interest and the SP wants to
be able to detect that this happened. To display appropriate information
to the user.
I tink I¹m actually fine with AuthnFailed in each of these cases.

The SP was just confused that it was wrapped in a ³Requester² error and
they wandered if they did anything wrong on their part.
As per the SAML standard recommendation, they ignored anyhing but the top
level error code.

/Stefan





More information about the users mailing list