Q in SP config and DS URL

Mike Manske michael.manske at ligo.org
Thu Feb 25 13:49:46 EST 2016


In an SP config, when specifying a DS URL for a SessionInitiator type
SAMLDS or when specifying discoveryURL for an SSO, why is a certificate not
used to validate the respective URLs?

Seems like a hole to me. Is it assumed the target URL is running under a
known SP?

We are thinking about central DS that many SPs use.

​Mike M
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160225/59c0ff82/attachment-0001.html>


More information about the users mailing list