Aw: Re: Re: Re: shibboleth - uncaught runtime exception on request
Ilya Rumyantsev
iliggio at gmx.de
Wed Dec 7 11:09:50 EST 2016
Thanks Scott, it works perfectly fine with saml2 only sp.
As it is a login for the DFN-AAI federation, I cannot assure everyone will be using SAML2. I'd need an error message to the user that the SP uses SAML 1 which is not supported (So that the saml 1 login is forbidden per se) At what point would I do it?
> Gesendet: Mittwoch, 07. Dezember 2016 um 16:58 Uhr
> Von: "Cantor, Scott" <cantor.2 at osu.edu>
> An: "Shib Users" <users at shibboleth.net>
> Betreff: Re: Aw: Re: Re: shibboleth - uncaught runtime exception on request
>
> On 12/7/16, 10:53 AM, "users on behalf of Ilya Rumyantsev" <users-bounces at shibboleth.net on behalf of iliggio at gmx.de> wrote:
>
> > The third-party SP speaks SAML 1, how would I avoid it for this request?
>
> If the third party SP is Shibboleth, and virtually nothing else would be querying for attributes, there's no reason it should require SAML 1. If it really does, then you can either push attributes to work around it, or use a NameID containing the DN so you can rely on that coming back in. That's it. Personally I would force them to get off SAML 1. Second choice would be to push the attributes.
>
> -- Scott
>
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>
More information about the users
mailing list