AuthnContextClassRef from SSP SP seeming to be ignored
Wessel, Keith
kwessel at illinois.edu
Wed Jan 11 15:41:24 EST 2017
Correct; Mike's not doing the work here. It is true, however, that the VM is named in his honor. Mike, long story; remind me to explain at Global Summit. :)
It turns out that the authncontextclassref I'm requesting in SSP is, in fact, not being passed onto the Shib IdP. So, this one's not Shib's fault. It's mine.
I'll read the thread Mike referenced and, if I'm still scratching my head, take this to the SSP list.
Sorry for the bother.
Keith
From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Michael A Grady
Sent: Wednesday, January 11, 2017 2:22 PM
To: Shib Users <users at shibboleth.net>
Subject: Re: AuthnContextClassRef from SSP SP seeming to be ignored
On Jan 11, 2017, at 1:54 PM, Cantor, Scott <cantor.2 at OSU.EDU<mailto:cantor.2 at OSU.EDU>> wrote:
If that's Mike Grady running the test here, and he wants to sanity check it against OSU's IdP, I can provide a context class for that to trigger Duo here. If that doesn't work, you will have my full attention and one end or the other has a bug.
Not involved with this ;-)
This is going to veer off a bit into SimpleSAML, I'll try to not go into any deeper on that.
Keith, it wasn't completely clear to me, is the SimpleSAML SP you are testing one that is defined as a saml:SP authentication source within the Proxy, or one that is external to the Proxy? What settings should get sent thru to a "proxied IdP" gets quite confusing when you talk about mixing up what the external SP asks for along with the settings of the "internal saml:SP authn source". I started a discussion on that on SimpleSAML's Google group back in early 2015:
https://groups.google.com/forum/#!topic/simplesamlphp/kMFZhJZFf3A<https://urldefense.proofpoint.com/v2/url?u=https-3A__groups.google.com_forum_-23-21topic_simplesamlphp_kMFZhJZFf3A&d=DQMFAg&c=8hUWFZcy2Z-Za5rBPlktOQ&r=Y0zzCBieYYCPPvkHk7LMZeVNTs2T9CLlF6pNSduPt_k&m=vOOY6wSOMmDbqbDj-9kcsyOVaTKis7pu8kVfC9H3gNI&s=S89-iUVDEhvc255lFCicKlZBLMVAreqQ51oARsy_LPo&e=>
it would be good to see the AuthnRequest coming into the Proxy to start things, and the AuthnRequest then being sent to the (I assume this is where Shib comes in) the proxied Shib IdP. But given that is all SimpleSAML up until the point the Shib IdP gets the AuthnRequest from the IdP Proxy, I don't think furhter discussion belongs here -- unless the AuthnRequest from the IdP Proxy clearly shows that it contained a requested AuthnContext of 'urn:mace:incommon:uiuc.edu<https://urldefense.proofpoint.com/v2/url?u=http-3A__uiuc.edu&d=DQMFAg&c=8hUWFZcy2Z-Za5rBPlktOQ&r=Y0zzCBieYYCPPvkHk7LMZeVNTs2T9CLlF6pNSduPt_k&m=vOOY6wSOMmDbqbDj-9kcsyOVaTKis7pu8kVfC9H3gNI&s=pZSJsroTlNIa__ZvJZb05uziZjmjwBz_BGvFD_bEHHQ&e=>:custom'.
--
Michael A. Grady
IAM Architect, Unicon, Inc.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170111/16235ff1/attachment.html>
More information about the users
mailing list