SAML1

Peter Schober peter.schober at univie.ac.at
Mon Mar 16 10:46:10 EDT 2015


* Arnal, Pascal <Pascal.Arnal at lacapitale.com> [2015-03-16 15:38]:
> OK, but I don't understand why the IDP work with SAML2 and not SAML1
> if it's an httpd conf ?

The Shib IDP will push attributes over the browser for SAML by default
(since SAML2 suppots XMLenc, meaning the attributes will be
unaccessible at the web browser), while by default the Shib IDP will
not push attributes unecrypted over the browser, causing the Shib SP
to issue an Attribute Query after it recieved the authentication
assertion but no attribute assertion/statement.
-peter


More information about the users mailing list