Q in SP config and DS URL

Cantor, Scott cantor.2 at osu.edu
Thu Feb 25 14:49:37 EST 2016


> In an SP config, when specifying a DS URL for a SessionInitiator type SAMLDS
> or when specifying discoveryURL for an SSO, why is a certificate not used to
> validate the respective URLs?

The SP isn't the one accessing it. And it's set by you, so if the value isn't a good one, you've just caused whatever bad outcome you're worried about.

The browser of course "validates" it if it's an https URL, but that of course is theater.
 
> Seems like a hole to me. Is it assumed the target URL is running under a
> known SP?

Which target URL are we talking about?

-- Scott



More information about the users mailing list