delegation in IDP3
Robert A Basch
rbasch at mit.edu
Wed Aug 10 17:13:22 EDT 2016
Just getting back to this...
Based on Brent's earlier comment that this had worked using another ID
type, I tried configuring the IdP to issue the emailAddress ID to the
SPs involved (instead of crypto transient). This still failed with the
same SubjectCanonicalization error, but no longer produced the "Transient
identifier issued to <SP1> but requested by <SP2>" warning also seen when
using crypto transient IDs.
Does this provide any additional clues about this, or how (if at all) we
might be able to work around the problem?
Should I file a new bug about this?
Thanks,
Bob
> On Jul 26, 2016, at 6:21 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
>
> On 7/26/16, 5:34 PM, "users on behalf of Brent Putman" <users-bounces at shibboleth.net on behalf of putmanb at georgetown.edu> wrote:
>
>>> it helps, I will note that we use CryptoTransient IDs in v2, which I believe
>>> is the default in v3. We actually ran into a bug there initially, which
>>> required a patch to the extension:
>>>
>>> https://issues.shibboleth.net/jira/browse/SIDP-606
>>>
>>
>> Yep, sounds like a very similar issue. Re-reading that I have absolutely no
>> recollection of doing that patch, but I guess we re-discovered the problem, and
>> essentially the same solution. :-)
>
> This isn't specific to the crypto variant in V3, though it may have been in V2 (which was a bug there). The RP checking is the same regardless of how the ID is generated, so switching wouldn't work around the issue.
>
> -- Scott
>
>
>
>
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list