Back-channel usage

Baron Fujimoto baron at hawaii.edu
Thu Mar 31 17:27:15 EDT 2016


I'm working on updating our IdP from v2 to v3. Per the advice of the
recommended wiki page at

<https://spaces.internet2.edu/display/InCFederation/Upgrading+to+Shibboleth+IdP+V3>

I'm trying to re-evaluate our need to support back-channel SAML protocols.
I apologize for the what's probably a dumb question, but how do I know
what back-channel protocols we currently have defined? I'm assuming, based
on our idp metadata and the information the the following pages

<https://spaces.internet2.edu/display/InCFederation/Protocol+Support+for+New+IdPs>
<https://wiki.shibboleth.net/confluence/display/IDP30/SecurityAndNetworking#SecurityAndNetworking-Back-ChannelSupport>

That we are supporting:

SAML1/SOAP/ArtifactResolution
SAML2/SOAP/ArtifactResolution
SAML1/SOAP/AttributeQuery
SAML2/SOAP/AttributeQuery

Are these the back-channel protocols, or am I already on the wrong track?
I don't think any of our SPs have requested them, and I don't see any
instances of these strings in any of our IdP logs (except where they are
loaded as a profile handler for the request path). Is this sufficient
evidence that they are not actually being used with our IdP?

-baron
-- 
Baron Fujimoto <baron at hawaii.edu> :: UH Information Technology Services
minutas cantorum, minutas balorum, minutas carboratum desendus pantorum


More information about the users mailing list