Where to specify which ACS to use for logging in?

Tom Scavo trscavo at gmail.com
Mon Dec 19 09:49:40 EST 2016


On Mon, Dec 19, 2016 at 9:31 AM, Cantor, Scott <cantor.2 at osu.edu> wrote:
>> Of the 2279 entities with an IdP role in InCommon metadata, zero of
>> them have a SAML2 HTTP-Artifact endpoint. I must be missing something.
>
> Inbound artifact support is not the same as supporting use of them outbound. The former relies on endpoints with that binding, the latter relies on an inbound ArtifactResolutionService (and it actually working).

I know that but the discussion here has not been clear. I responded to
what I thought I heard, maybe I heard wrong.

For a particular IdP and SP to successfully use artifact, one of them
needs an HTTP-Artifact endpoint in metadata while the other needs an
ArtifactResolutionService endpoint. The two are complementary.

Since there are no HTTP-Artifact endpoints in IdP metadata, that use
case is nonexistent, yet that's exactly the use case I "heard" ScottK
describe (so I must have heard incorrectly).

Tom


More information about the users mailing list