Sending AuthRequest without ACS

Cantor, Scott cantor.2 at osu.edu
Tue Nov 1 14:14:53 EDT 2016


> On Tue, Nov 1, 2016 at 2:10 PM, Rainer Hoerbe <rainer at hoerbe.at> wrote:
> The SP metadata is wrong. The ACS endpoint should be associated with
> the HTTP-POST binding, not HTTP-Redirect. Sending a SAML response via
> HTTP-Redirect is not feasible.

Ah, good catch. I was just about to check whether the AuthnRequest had the ProtocolBinding set to something that wasn't kosher.

The unsolicited endpoint essentially *is* this case, if you don't give it the shire parameter, so it didn't seem possible this could be a bug in general.

-- Scott



More information about the users mailing list