Incoming binding urn:oasis:names:tc:SAML:2.0:bindings:SOAP is not enabled for (SP) :::
Tom Scavo
trscavo at gmail.com
Sun Nov 26 13:20:42 EST 2017
On Sun, Nov 26, 2017 at 11:54 AM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> On 11/23/17, 10:52 AM, "users on behalf of Tom Scavo" <users-bounces at shibboleth.net on behalf of trscavo at gmail.com> wrote:
>
>> Then the IdP does not support attribute query. Instead of swimming
>> upstream, ask the IdP to push attributes on the front-channel instead.
>
> And in virtually all such cases the "error" is that they aren't releasing any data to you. Making queries won't change that even if they "worked".
That's right. To put this into perspective, there are 2577 entities in
eduGAIN metadata that support SAML2 SSO (Redirect or POST). Of those,
988 entities contain a redundant SAML2 AttributeService endpoint
(assuming the IdP pushes attributes on the front channel in all
cases).
Tom
More information about the users
mailing list