Aw: Re: Re: Re: shibboleth - uncaught runtime exception on request

Cantor, Scott cantor.2 at osu.edu
Wed Dec 7 11:28:56 EST 2016


On 12/7/16, 11:09 AM, "users on behalf of Ilya Rumyantsev" <users-bounces at shibboleth.net on behalf of iliggio at gmx.de> wrote:

> As it is a login for the DFN-AAI federation, I cannot assure everyone will be using SAML2. I'd need an error message to the
> user that the SP uses SAML 1 which is not supported (So that the saml 1 login is forbidden per se)

Why? Just push attributes.

> At what point would I do it?

If you want to block SAML 1, pull it from the profile config list for the relying party definition being used.

-- Scott




More information about the users mailing list