Incoming binding urn:oasis:names:tc:SAML:2.0:bindings:SOAP is not enabled for (SP) :::
Cantor, Scott
cantor.2 at osu.edu
Sun Nov 26 13:34:15 EST 2017
(And yes, we're going to turn off the auto-querying functionality in 3.0, it's just taken a long time to get to a 3.0 and finally take care of it.)
-- Scott
On 11/26/17, 1:20 PM, "users on behalf of Tom Scavo" <users-bounces at shibboleth.net on behalf of trscavo at gmail.com> wrote:
On Sun, Nov 26, 2017 at 11:54 AM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> On 11/23/17, 10:52 AM, "users on behalf of Tom Scavo" <users-bounces at shibboleth.net on behalf of trscavo at gmail.com> wrote:
>
>> Then the IdP does not support attribute query. Instead of swimming
>> upstream, ask the IdP to push attributes on the front-channel instead.
>
> And in virtually all such cases the "error" is that they aren't releasing any data to you. Making queries won't change that even if they "worked".
That's right. To put this into perspective, there are 2577 entities in
eduGAIN metadata that support SAML2 SSO (Redirect or POST). Of those,
988 entities contain a redundant SAML2 AttributeService endpoint
(assuming the IdP pushes attributes on the front channel in all
cases).
Tom
--
For Consortium Member technical support, see https://wiki.shibboleth.net/confluence/x/coFAAg
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list