(SP1-->IdP1 (simple profile)) -->SP2-->IdP2(resolve artifact profile).
David Tildesley
davotnz at yahoo.co.nz
Fri Mar 20 00:59:45 EDT 2015
Hi Scott,
Can I verify with you that the SP can work with an IdP that uses the "Artifact Binding" and can resolve the artefact by calling a soap service presented by the IdP?
The documentation indicates this is possible but it is an oblique reference under a title called "NativeSPBackDoor" as quoted below:
"One of the supported mechanisms takes advantage of the less-commonly used SAML binding called the "Artifact Binding". Instead of pushing a SAML response through the client, an encoded reference called an "artifact" is generated by the IdP, passed to the SP via a redirect, and then the SP turns the artifact into the SAML response using a SOAP request."
Is there another part of the documentation that explains how to configure the above?
Regards,
David.
On Monday, 9 March 2015 11:59 AM, "Cantor, Scott" <cantor.2 at osu.edu> wrote:
On 3/8/15, 6:50 PM, "David Tildesley" <davotnz at yahoo.co.nz> wrote:
>Is this achievable with "back to back" connection of Shibboleth Identity and Service Provider instances?
It's achievable, but if you weren't already planning to use Apache as the web server for the IdP, it adds an additional layer. There's also no current data connector within the IdP that will pull data from the headers to use downstream, though that will get fixed in the next couple of releases.
We didn't design the IdP to function as a gateway, and a lot of people use simpleSAML.php for that use case.
-- Scott
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20150320/6cbdf683/attachment.html
More information about the users
mailing list