SAML Token?

Peter Schober peter.schober at univie.ac.at
Thu Apr 26 05:08:59 EDT 2018


* Simon Lundström <simlu at su.se> [2018-04-26 10:52]:
> On Thu, 2018-04-26 at 08:55:25 +0200, Peter Schober wrote:
> >* Peter Smith <Peter.Smith at UTSouthwestern.edu> [2018-04-26 00:50]:
> >>And actually, now that we have this "SAML Token" we can now move on
> >>to testing their SP.
> >
> >And this worked using only a "32-character hex string" how?
> 
> Can't it just be the entityID?

I guess, provided the SP will somehow generate an authn request with
the protocol endpoint in it, which you can then provision to metadata
at the IDP.
And of course provided you're willing to forgo encryption with the SP
(as there's no key).

-peter


More information about the users mailing list