Sending AuthRequest without ACS
Cantor, Scott
cantor.2 at osu.edu
Tue Nov 1 14:14:53 EDT 2016
> On Tue, Nov 1, 2016 at 2:10 PM, Rainer Hoerbe <rainer at hoerbe.at> wrote:
> The SP metadata is wrong. The ACS endpoint should be associated with
> the HTTP-POST binding, not HTTP-Redirect. Sending a SAML response via
> HTTP-Redirect is not feasible.
Ah, good catch. I was just about to check whether the AuthnRequest had the ProtocolBinding set to something that wasn't kosher.
The unsolicited endpoint essentially *is* this case, if you don't give it the shire parameter, so it didn't seem possible this could be a bug in general.
-- Scott
More information about the users
mailing list