idp v3 - unsolicited sso failing

Cantor, Scott cantor.2 at osu.edu
Sun Mar 15 19:29:24 EDT 2015


On 3/15/15, 7:23 PM, "Marc Boorshtein" <mboorshtein at gmail.com> wrote:
>
>No, I'm saying the metadata flag from wanting authnrequests signed is not applicable to unsolicited sso because unsolicited sso is not the same thing as an authnrequest thats part of an sp initiated sso.

And I don't agree with that.

>OK, but this is a verifiable and repeatable issue.
>SP initiated SSO generates an AuthnRequest that is NOT signed which shib accepts but an unsolicited SSO fails.

My only explanation, given the testing I literally did 90 seconds ago in my sandbox, is that the message is in fact signed. My own testing was with Redirect, I can try POST and make sure that doesn't alter the result.

-- Scott



More information about the users mailing list