Q in SP config and DS URL

Mike Manske michael.manske at ligo.org
Thu Feb 25 16:55:55 EST 2016


On Thu, Feb 25, 2016 at 1:49 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:

> > In an SP config, when specifying a DS URL for a SessionInitiator type
> SAMLDS
> > or when specifying discoveryURL for an SSO, why is a certificate not
> used to
> > validate the respective URLs?
>
> The SP isn't the one accessing it. And it's set by you, so if the value
> isn't a good one, you've just caused whatever bad outcome you're worried
> about.
>
> The browser of course "validates" it if it's an https URL, but that of
> course is theater.
>
> > Seems like a hole to me. Is it assumed the target URL is running under a
> > known SP?
>
> Which target URL are we talking about?
>
> -- Scott
>

​The URL of the DS, for example, the Shibboleth EDS.​


>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160225/32e6208d/attachment.html>


More information about the users mailing list