Validate InResponseTo attribute

Paolo Smiraglia paolo.smiraglia at gmail.com
Wed Jan 9 11:16:47 EST 2019


On Wed, 9 Jan 2019 at 16:36, Cantor, Scott <cantor.2 at osu.edu> wrote:
>
> [...]
>
> No, because just requiring an InResponseTo would mean nothing without the ability to know what the original request ID was to begin with.

So, from your answers I have to assume that with Shibboleth SP there
is no way to verify the "inResponseTo" attibute. Is it correct?

If so, why this feature was not included? Is it because Web Browser
SSO supports "unsolicited responses" [1, Sec 4.1.5]?

Have you some alternative strategy to address the "InResponseTo" validation?

Many thanks,

   Paolo

[1] http://docs.oasis-open.org/security/saml/v2.0/saml-profiles-2.0-os.pdf

-- 
PAOLO SMIRAGLIA


More information about the users mailing list