Shib IdP 3 and IOP online service

Rod Widdowson rdw at steadingsoftware.com
Tue Mar 24 07:14:18 EDT 2015


> Releasing attributes to SAML2 SPs works.

To clarify, does that mean that SP is demanding SAML1?  The metadata I'm looking at suggests not at first blush.

But then they also appear to be being doing something odd with discovery to do with per federation responses, and then end up with a Shibboleth (SAML1) query.

I've just tested a SAML1 sp against a V3 IdP (with attribute pull) and it did "what I expected" (show attribute screen and then release them), so it's not a simple bug.

More by way of straw-grasping, can you force the artefact profile and see what happens:

<youtIdP>/idp/profile/Shibboleth/SSO?shire=https%3A%2F%2Fticket.iop.org%2FShibboleth.sso%2FSAML%2FArtifact&target=cookie%3A015f5922&providerId=https%3A%2F%2Fticket.iop.org%2Fshibboleth







More information about the users mailing list