SAML2 attribute query authentication for IdPv3
Scott Koranda
skoranda at gmail.com
Mon Sep 14 17:41:11 EDT 2015
> > On 9/14/15, 10:30 AM, "users on behalf of Scott Koranda" <users-bounces at shibboleth.net on behalf of skoranda at gmail.com> wrote:
> >
> > >If I decide to try and instead have the client authenticate by
> > >signing the attribute query, do I need to make any
> > >configuration changes to the IdPv3 or will this "just work".
> >
> > It should just work in either V2 or V3. We have a stack of
> > rules and as long as one of them succesfully authenticates
> > the requester, it should be equivalent.
>
> Thanks.
>
> Since I control both the IdPv3 attribute authority and the
> Shib SPs, I would find it instructive to have a Shib SP send a
> signed attribute query rather than using TLS client
> authentication.
>
> I looked at the documentation for the SimpleAggregation
> AttributeResolver but I do not see a configuration option to
> "force" the use of a digital signature on the attribute query
> rather than TLS client authentication.
>
> Is there a way for me to force a Shib SP to send a signed
> attribute query?
>
Nevermind. I see the relying party attributes that allow me to
configure this:
https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPApplication
Sorry for the noise,
Scott K
More information about the users
mailing list