idp v3 - unsolicited sso failing
Cantor, Scott
cantor.2 at osu.edu
Sun Mar 15 19:29:24 EDT 2015
On 3/15/15, 7:23 PM, "Marc Boorshtein" <mboorshtein at gmail.com> wrote:
>
>No, I'm saying the metadata flag from wanting authnrequests signed is not applicable to unsolicited sso because unsolicited sso is not the same thing as an authnrequest thats part of an sp initiated sso.
And I don't agree with that.
>OK, but this is a verifiable and repeatable issue.
>SP initiated SSO generates an AuthnRequest that is NOT signed which shib accepts but an unsolicited SSO fails.
My only explanation, given the testing I literally did 90 seconds ago in my sandbox, is that the message is in fact signed. My own testing was with Redirect, I can try POST and make sure that doesn't alter the result.
-- Scott
More information about the users
mailing list