(SP1-->IdP1 (simple profile)) -->SP2-->IdP2(resolve artifact profile).

Cantor, Scott cantor.2 at osu.edu
Fri Mar 20 09:55:05 EDT 2015


On 3/20/15, 12:59 AM, "David Tildesley" <davotnz at yahoo.co.nz> wrote:
>
>Can I verify with you that the SP can work with an IdP that uses the "Artifact Binding" and can resolve the artefact by calling a  soap service presented by the IdP?

Yes.

>The documentation indicates this is possible but it is an oblique reference under a title called "NativeSPBackDoor" as quoted below:  

That has nothing to do with standard artifact usage, that's about a trick used to leverage that code to do something unrelated.

>"One of the supported mechanisms takes advantage of the less-commonly
> used SAML binding called the "Artifact Binding". Instead of pushing a SAML response through the client, an encoded reference called an "artifact" is generated by the IdP, passed to the SP via a redirect, and then the SP turns the artifact into the SAML response
> using a SOAP request."
>
>Is there another part of the documentation that explains how to configure
> the above?

I'm not sure what you're asking about. That is the page that talks about the backdoor feature. But I don't think that's what you're actually trying to do.

There's not much to say about artifact otherwise. It's supported automatically, inbound at least.

-- Scott



More information about the users mailing list