idp v3 - unsolicited sso failing

Marc Boorshtein mboorshtein at gmail.com
Sun Mar 15 14:35:09 EDT 2015


While I understand your argument, it goes counter to most other SAML
products. Adfs, openam, oif, ping, etc all work this way. Also you aren't
circumventing signing the authn request you are kicking off authentication
directly from the idp so its not exactly the same thing.

Thanks
Marc
On Mar 15, 2015 1:23 PM, "Cantor, Scott" <cantor.2 at osu.edu> wrote:

> On 3/15/15, 12:00 PM, "Marc Boorshtein" <mboorshtein at gmail.com> wrote:
>
> >It looks like the idp is looking for an authnrequest even though one
> doesn't exist.  Is this a bug?
>
> That's debateable. I don't know what V2 did/does in this case, but even if
> it "works", I could make a pretty strong case that the V2 behavior is the
> bug. I don't think I'm inclined to change this. If the metadata says the SP
> signs its requests, you shouldn't be able to circumvent that, it would make
> the feature worthless.
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20150315/252fa934/attachment.html 


More information about the users mailing list