IdP Unsolicited SSO & endpoint checking
Alex Olson
ako at byu.edu
Mon Jan 11 14:43:26 EST 2016
Hi there,
We are currently running shib idp v2.4.x (planning on upgrading soon).
We have a vendor that wants to use our IdP for authentication. It requires us using the unsolicited sso feature of the idp. They do however, have a dynamic ACS url, and there’s no way we could list of all of them in their metadata. I know that when going through ‘normal’ SAML flow you can disable endpoint checking on the idp side if the request is signed from the sp, but is there any way to achieve similar functionality using the unsolicited sso endpoint? Currently they pass in their ACS url via the ‘shire’ parameter but since it’s dynamically generated it won’t be found in their metadata.
Although, this feels like a giant security hole to me so perhaps the better question is how would you go about supporting an sp that requires use of the unsolicted sso endpoint but also has a dynamic ACS url. The actual URL itself stays the same but the query parameters change.
-- Alex
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160111/a586489c/attachment.html>
More information about the users
mailing list