AuthnContextClassRef from SSP SP seeming to be ignored

Michael A Grady mgrady at unicon.net
Wed Jan 11 15:22:00 EST 2017


> On Jan 11, 2017, at 1:54 PM, Cantor, Scott <cantor.2 at OSU.EDU> wrote:
> 
> If that's Mike Grady running the test here, and he wants to sanity check it against OSU's IdP, I can provide a context class for that to trigger Duo here. If that doesn't work, you will have my full attention and one end or the other has a bug.

Not involved with this  ;-)

This is going to veer off a bit into SimpleSAML, I'll try to not go into any deeper on that.

Keith, it wasn't completely clear to me, is the SimpleSAML SP you are testing one that is defined as a saml:SP authentication source within the Proxy, or one that is external to the Proxy? What settings should get sent thru to a "proxied IdP" gets quite confusing when you talk about mixing up what the external SP asks for along with the settings of the "internal saml:SP authn source". I started a discussion on that on SimpleSAML's Google group back in early 2015:

  https://groups.google.com/forum/#!topic/simplesamlphp/kMFZhJZFf3A <https://groups.google.com/forum/#!topic/simplesamlphp/kMFZhJZFf3A>

it would be good to see the AuthnRequest coming into the Proxy to start things, and the AuthnRequest then being sent to the (I assume this is where Shib comes in) the proxied Shib IdP. But given that is all SimpleSAML up until the point the Shib IdP gets the AuthnRequest from the IdP Proxy, I don't think furhter discussion belongs here -- unless the  AuthnRequest  from the IdP Proxy clearly shows that it contained a requested AuthnContext of 'urn:mace:incommon:uiuc.edu:custom'.


--
Michael A. Grady
IAM Architect, Unicon, Inc.



-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170111/8b805677/attachment.html>


More information about the users mailing list