Where to specify which ACS to use for logging in?

Br LRd blasterradius at gmail.com
Fri Dec 16 10:25:22 EST 2016


 >The IdP gets them from the SP, that's the message sent from the SP
through the client to the IdP. I doubt that's what you meant to ask, but
that's what you literally asked.

Where does the SP get them from? I assume from shibboleth2.xml or
protocols.xml, but I'm not sure what to change there exactly. What changes
the values of AssertionConsumerServiceURL and ProtocolBinding in a
authnrequest?

On Fri, Dec 16, 2016 at 5:16 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:

> On 12/16/16, 9:56 AM, "users on behalf of Br LRd" <
> users-bounces at shibboleth.net on behalf of blasterradius at gmail.com> wrote:
>
> > Logging in to <>/Shibboleth.so/Login,
>
> You don't "login to that", that's an endpoint at the SP that can be used
> to cause it to generate a request to the IdP for an assertion to be
> delivered to the SP, get a session created, and redirect to a target
> resource or the homeURL.
>
> > this is how the assertion looks:
>
> No, that's what a SAML AuthnRequest looks like, that's not an assertion.
>
> > Where does shibboleth/IDP get the AssertionConsumerServiceURL and
> ProtocolBinding values from?
>
> The IdP gets them from the SP, that's the message sent from the SP through
> the client to the IdP. I doubt that's what you meant to ask, but that's
> what you literally asked.
>
> -- Scott
>
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20161216/573739e7/attachment.html>


More information about the users mailing list