Securely passing
Peter Schober
peter.schober at univie.ac.at
Fri Dec 7 11:31:33 EST 2018
* Michael A Grady <mgrady at unicon.net> [2018-12-07 17:21]:
> Yes, Unicon's Shib-CAS-Authn3 extension for the IdP (using a
> separate CAS Server for the authentication) uses that
> ExternalAuthnConfiguration method, and indeed does pass the SP
> entityID across. so that can be done as Peter notes.
I'm guessing if one was concerned about the authenticity of such
parameters one could add another parameter with a checksum or
signature, since the code on both sides (the component running within
the IDP, the external authentication service) would need to be custom
anyway?
-peter
More information about the users
mailing list