Q in SP config and DS URL
Peter Schober
peter.schober at univie.ac.at
Thu Feb 25 13:54:17 EST 2016
* Mike Manske <michael.manske at ligo.org> [2016-02-25 19:50]:
> In an SP config, when specifying a DS URL for a SessionInitiator type
> SAMLDS or when specifying discoveryURL for an SSO, why is a certificate not
> used to validate the respective URLs?
Not used for validation by whom? That's URL goes into an HTTP
'Location' response header and the HTTP User Agent will probably
access that (i.e., follow the redirect). So it's the subject's web
browser that does the TLS verification, same as everywhere else on the
web?
-peter
More information about the users
mailing list