3.4.8 warning

Cantor, Scott cantor.2 at osu.edu
Thu Jul 29 18:12:49 UTC 2021


On 7/29/21, 1:56 PM, "users on behalf of Donald Lohr" <users-bounces at shibboleth.net on behalf of lohrda at jmu.edu> wrote:

>    I am not aware of any CAS SPs, I've seen reference of what seems like a 
>    CAS service running from evidence in the logs, but have not researched 
>    or verified that one.

There should at least be proximity in the log if it's the one triggering the warning but a policy requirement rule that relies on SAML metadata to run is going to be evaluated on every request to decide whether to apply it, including a CAS service.

I would have to review whether WARN is the appropriate level for the message or not. Possibly it's already been turned down, I don't know.

>    How would I begin to find if we are "running promiscuously with SSO 
>    enabled for unverified relying parties" ?

One of the earlier beans in relying-party.xml is the set of profiles enabled for anonymous/unverified RPs. That concept dates back to at least V2 and possibly V1. Most IdPs don't enable any profiles for use that way. I assume some do.

-- Scott




More information about the users mailing list