3.4.8 warning
Cantor, Scott
cantor.2 at osu.edu
Thu Jul 29 18:12:49 UTC 2021
On 7/29/21, 1:56 PM, "users on behalf of Donald Lohr" <users-bounces at shibboleth.net on behalf of lohrda at jmu.edu> wrote:
> I am not aware of any CAS SPs, I've seen reference of what seems like a
> CAS service running from evidence in the logs, but have not researched
> or verified that one.
There should at least be proximity in the log if it's the one triggering the warning but a policy requirement rule that relies on SAML metadata to run is going to be evaluated on every request to decide whether to apply it, including a CAS service.
I would have to review whether WARN is the appropriate level for the message or not. Possibly it's already been turned down, I don't know.
> How would I begin to find if we are "running promiscuously with SSO
> enabled for unverified relying parties" ?
One of the earlier beans in relying-party.xml is the set of profiles enabled for anonymous/unverified RPs. That concept dates back to at least V2 and possibly V1. Most IdPs don't enable any profiles for use that way. I assume some do.
-- Scott
More information about the users
mailing list