Q in SP config and DS URL

Peter Schober peter.schober at univie.ac.at
Thu Feb 25 13:54:17 EST 2016


* Mike Manske <michael.manske at ligo.org> [2016-02-25 19:50]:
> In an SP config, when specifying a DS URL for a SessionInitiator type
> SAMLDS or when specifying discoveryURL for an SSO, why is a certificate not
> used to validate the respective URLs?

Not used for validation by whom?  That's URL goes into an HTTP
'Location' response header and the HTTP User Agent will probably
access that (i.e., follow the redirect). So it's the subject's web
browser that does the TLS verification, same as everywhere else on the
web?
-peter


More information about the users mailing list