SAML2 attribute query authentication for IdPv3

Scott Koranda skoranda at gmail.com
Mon Sep 14 17:25:01 EDT 2015


> On 9/14/15, 10:30 AM, "users on behalf of Scott Koranda" <users-bounces at shibboleth.net on behalf of skoranda at gmail.com> wrote:
> 
> >If I decide to try and instead have the client authenticate by
> >signing the attribute query, do I need to make any
> >configuration changes to the IdPv3 or will this "just work".
> 
> It should just work in either V2 or V3. We have a stack of
> rules and as long as one of them succesfully authenticates
> the requester, it should be equivalent.
 
Thanks.

Since I control both the IdPv3 attribute authority and the
Shib SPs, I would find it instructive to have a Shib SP send a
signed attribute query rather than using TLS client
authentication.

I looked at the documentation for the SimpleAggregation
AttributeResolver but I do not see a configuration option to
"force" the use of a digital signature on the attribute query
rather than TLS client authentication.

Is there a way for me to force a Shib SP to send a signed
attribute query?

Thanks,

Scott K


More information about the users mailing list