Q in SP config and DS URL
Cantor, Scott
cantor.2 at osu.edu
Thu Feb 25 14:49:37 EST 2016
> In an SP config, when specifying a DS URL for a SessionInitiator type SAMLDS
> or when specifying discoveryURL for an SSO, why is a certificate not used to
> validate the respective URLs?
The SP isn't the one accessing it. And it's set by you, so if the value isn't a good one, you've just caused whatever bad outcome you're worried about.
The browser of course "validates" it if it's an https URL, but that of course is theater.
> Seems like a hole to me. Is it assumed the target URL is running under a
> known SP?
Which target URL are we talking about?
-- Scott
More information about the users
mailing list