IdP v3 not releasing attributes to SAML1 SPs
Mark K. Miller
max at psu.edu
Mon Aug 22 12:22:48 EDT 2016
On Mon, 22 Aug 2016, Cantor, Scott wrote:
>> I've had a few more reports today of SPs not working. The first thing
>> I've noticed in the idp-process.log is that these SP are all still using
>> SAML1. It appears that the authentication happens without issue, but I'm
>> not seeing any attributes get sent to these SAML1 SPs.
>
> I would imagine you broke the back-channel in some way and queries
> aren't working.
I certainly didn't intend to change anything at all about the back-channel.
>> Is this something that's know to break in the v2-to-v3 upgrade?
>
> It's entirely identical
Not after our IdP was upgraded, it's not. :-(
> save for how transient IDs are generated and
> reversed by default.
>
> -- Scott
On a more positive note, at least two thirds of the vendors have seemed
very cooperative about changing their SP from SAML1 to SAML2 (so far.)
Thanks,
Max
More information about the users
mailing list