Incoming binding urn:oasis:names:tc:SAML:2.0:bindings:SOAP is not enabled for (SP) :::

Cantor, Scott cantor.2 at osu.edu
Wed Nov 29 11:36:15 EST 2017


On 11/29/17, 11:29 AM, "users on behalf of Pruvost, Christian (ELS-OXF)" <users-bounces at shibboleth.net on behalf of c.pruvost at elsevier.com> wrote:

> It also means that you do not necessarily need a KeyDescriptor with a signing certificate for attributeQuery requests when you
> are using another port than 443 (e.g. 9443) and a simple certificate exchange to be able to perform the Attribute
> Query query request over a TLS (SSL) is working fine.

If we're talking about Shibboleth, the SP will not accept a query response from an IdP without a key in its AA role in metadata, at least not unless you turn off security. It won't even connect to a back channel port by default because it requires transport authentication on any non-443 port. If you have evidence otherwise, you should report a security bug.

If this isn't Shibboleth, then you most definitely have a security bug, but it's not any of my business.

-- Scott




More information about the users mailing list