Back-channel usage

Cantor, Scott cantor.2 at osu.edu
Thu Mar 31 17:44:07 EDT 2016


> I apologize for the what's probably a dumb question, but how do I know
> what back-channel protocols we currently have defined?

Defined in...? Your old IdP? A default V3 install?

> I'm assuming,
> based on our idp metadata and the information the the following pages

The only metadata that matters is what somebody else sees. InCommon. etc. And that isn't what you "have defined", it's what you advertise. It's possible because of mistakes to advertise something you don't really have configured. The other way around is also certainly possible.

> That we are supporting:
> 
> SAML1/SOAP/ArtifactResolution
> SAML2/SOAP/ArtifactResolution
> SAML1/SOAP/AttributeQuery
> SAML2/SOAP/AttributeQuery

That is the typical situation historically and is what V3 comes configured with (plus Logout I guess).

> Are these the back-channel protocols, or am I already on the wrong track?

Yes, the back channel endpoints all have /SOAP in them right now except for CAS stuff.

> I don't think any of our SPs have requested them, and I don't see any
> instances of these strings in any of our IdP logs (except where they are
> loaded as a profile handler for the request path). Is this sufficient
> evidence that they are not actually being used with our IdP?

The web access logs are the absolute definitive evidence.

-- Scott



More information about the users mailing list