SingleSignOnService
Liam Hoekenga
liamr at umich.edu
Fri Dec 2 12:54:53 EST 2016
Acc'd to the SAML spec, the IDPSSODescriptor element must include at least
one SingleSignOnService:
https://docs.oasis-open.org/security/saml/v2.0/saml-metadata-2.0-os.pdf
2.4.3 Element <IDPSSODescriptor>
<SingleSignOnService> [One or More]
One or more elements of type EndpointType that describe endpoints that
support the profiles of
the Authentication Request protocol defined in [SAMLProf]. All identity
providers support at least
one such endpoint, by definition. The ResponseLocation attribute MUST be
omitted.
Liam
On Fri, Dec 2, 2016 at 11:43 AM, Sam Jacob <skjacob at gmail.com> wrote:
> IDP provided their metadata file and it's missing the SingleSignOnService
> tag in the XML file.
> and shib is giving an error: "metadata instance failed manual validation
> checking: IDPSSODescriptor must have at least one SingleSignOnService. "
>
> is "SingleSignOnService" a required attribute?
> Can SSO work without "SingleSignOnService" ?
>
> thanks
>
> --
> Sam Jacob
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20161202/17245f4b/attachment.html>
More information about the users
mailing list