Anonymous RP / ECP / SSO profiles / encryption
Terbu Oliver
terbu at staatsdruckerei.at
Tue Jan 17 08:07:36 EST 2017
Hi,
I was looking into Shibboleth SAML profiles. It seems that Shibboleth supports anonymous SPs which is called AnonymousRelyingParty. Could this be used to bypass out-of-band registration? Are anonymous RPs Shibboleth specific, or does SAML 2.0 generally does not enforce SP registration? Furthermore, I would like to force encryption of assertions or attributes. Is there a way in SAML 2.0 to include the certificate/public key of the SP in the AuthnRequest which could be used for encryption?
Generally, I would like to know if the Service Provider (SP) has to be always known to the IdP according to the SAML 2.0 specification (e.g. out-of-band registration)?
Thanks and best regards,
Oliver
More information about the users
mailing list