Specified AssertionConsumerService Location as Relative Url

Surinaidu Majji pioneer.suri at gmail.com
Mon Jun 29 09:13:12 EDT 2015


Configure the SP to sign authn requests and configiure the IDP to
ignore ACS URL checks for (correctly) signed authn requests.

>>  It would be great if you can mention How to ignore ACS URL checks in
IDP(3.1.1)?

On Mon, Jun 29, 2015 at 4:13 PM, Peter Schober <peter.schober at univie.ac.at>
wrote:

> * Surinaidu Majji <pioneer.suri at gmail.com> [2015-06-29 07:24]:
> > From the above in (i), We have given absoluteUrl when sending saml
> > request but in metadata "Location" is "/SSOServiceProvider/SSO"
> > which is relative.
>
> Relative to where, I wonder. Seems to me doing that doesn't provide
> any security about where the protocol message (with attributes etc.)
> is going. Which is the point of having metadata for the SP.
>
> > a) Since the context (http(s)://ipaddress:port) is dynamic, How to
> > make the application work by specifying "relativeUrl"
> > (/SSOServiceProvider/SSO) in SP metadata?
>
> Configure the SP to sign authn requests and configiure the IDP to
> ignore ACS URL checks for (correctly) signed authn requests.
> -peter
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20150629/b12f7d68/attachment.html>


More information about the users mailing list