Backchannel failing after upgrade

Cantor, Scott cantor.2 at osu.edu
Fri Jan 20 15:41:35 EST 2017


On 1/20/17, 3:36 PM, "users on behalf of James Drews" <users-bounces at shibboleth.net on behalf of james.drews at wisc.edu> wrote:

>    The explanation I got was we have sites that will accept authentication from different IDP's. The configuration has the
> <AttributeResolver type="Query"> set to turn around and ask the IDP used for authentication for the attributes.

That plugin is for SAML 1.1 use and dates back to the transition phase to SAML 2.0. You don't need to be supporting queries and if it's being used, you're either using SAML 1.1, which should be addressed by migrating to SAML 2.0, or you're not sending them any attributes because of policy, which won't change if they query for them.

SAML 2.0 SSO includes the attributes, there's no query.

-- Scott




More information about the users mailing list