Unsolicited SSO with AuthnRequestsSigned="true" SP metadata
Santu Ghosh
mon.snahasish at gmail.com
Tue Nov 28 13:20:25 EST 2017
Thanks Peter and Scott,
To clarify my understanding from the discussions is that there are
*ONLY 2* possible
solutions for the mentioned problem.
1) If I want to proceed with unsolicited SSO, I *HAVE TO* remove
WantAssertionsSigned="true"
from my SP metadata file *EACH AND EVERY* time before reloading it in IDP.
2) I can proceed with SP initiated flow, then no modification require in SP
metadata.
there are no options (solutions) available for IDP side change and it
should not.
Please correct me if I am understanding wrong.
Snahasish
On Tue, Nov 28, 2017 at 11:33 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> > I'm not aware of a configuration in the IDP that would allow it to
> > ignore the SP's explicit request to reject unsigned authrequests
> > (since that would make it non-conformant) I wouldn't be surprised if
> > the IDP could in fact be configured to allow for that.
>
> No, there isn't one since it would defeat the purpose of even supporting
> the flag in the metadata. There also isn't an exposed way to explicitly
> toggle off support for that flag being honored, as nobody has filed such a
> request.
>
> -- Scott
>
> --
> For Consortium Member technical support, see https://wiki.shibboleth.net/
> confluence/x/coFAAg
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20171128/458f3794/attachment-0001.html>
More information about the users
mailing list