SAML2 attribute query authentication for IdPv3

Scott Koranda skoranda at gmail.com
Mon Sep 14 17:41:11 EDT 2015


> > On 9/14/15, 10:30 AM, "users on behalf of Scott Koranda" <users-bounces at shibboleth.net on behalf of skoranda at gmail.com> wrote:
> > 
> > >If I decide to try and instead have the client authenticate by
> > >signing the attribute query, do I need to make any
> > >configuration changes to the IdPv3 or will this "just work".
> > 
> > It should just work in either V2 or V3. We have a stack of
> > rules and as long as one of them succesfully authenticates
> > the requester, it should be equivalent.
>  
> Thanks.
> 
> Since I control both the IdPv3 attribute authority and the
> Shib SPs, I would find it instructive to have a Shib SP send a
> signed attribute query rather than using TLS client
> authentication.
> 
> I looked at the documentation for the SimpleAggregation
> AttributeResolver but I do not see a configuration option to
> "force" the use of a digital signature on the attribute query
> rather than TLS client authentication.
> 
> Is there a way for me to force a Shib SP to send a signed
> attribute query?
> 

Nevermind. I see the relying party attributes that allow me to
configure this:

https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPApplication

Sorry for the noise,

Scott K



More information about the users mailing list