Validate InResponseTo attribute
Paolo Smiraglia
paolo.smiraglia at gmail.com
Wed Jan 9 11:16:47 EST 2019
On Wed, 9 Jan 2019 at 16:36, Cantor, Scott <cantor.2 at osu.edu> wrote:
>
> [...]
>
> No, because just requiring an InResponseTo would mean nothing without the ability to know what the original request ID was to begin with.
So, from your answers I have to assume that with Shibboleth SP there
is no way to verify the "inResponseTo" attibute. Is it correct?
If so, why this feature was not included? Is it because Web Browser
SSO supports "unsolicited responses" [1, Sec 4.1.5]?
Have you some alternative strategy to address the "InResponseTo" validation?
Many thanks,
Paolo
[1] http://docs.oasis-open.org/security/saml/v2.0/saml-profiles-2.0-os.pdf
--
PAOLO SMIRAGLIA
More information about the users
mailing list