IdP v4 saml response size

Martin Haase Martin.Haase at DAASI.de
Fri Mar 5 11:31:52 UTC 2021


Thanks Peter,

encryption... the obvious. We'll give it a try. At least until this SP
will be have been fixed.

Cheers

Martin

Am 05.03.21 um 11:25 schrieb Peter Schober:
> * Martin Haase <Martin.Haase at DAASI.de> [2021-03-05 08:53]:
>> Regarding attributes, there is no option to send less. Any other
>> ideas?
> Well, what is it about IDPv4 that made the response bigger?
>
> Not signing certainly certainly isn't an option (though maybe moving
> the signaure elsewhere, if Response then sign the Assertion or vice
> versa) avoids this?
>
> Not encrypting (as that should also include the cert the IDP
> encrytpted it to) and relying on TLS only might be acceptable and
> probably has the largest potential for size reduction.
>
> Use the backchannel (attribute queries, artifacts)?
> Using the HTTP-POST-SimpleSign protocol binding might also change this
> a bit but if they support that they'd very likely be running a
> Shibboleth SP and that has no issues with response sizes to begin
> with.
>
> Do they look at the NameID? If not maybe not sending one makes a difference.
> Do they check NameFormats of attributes? Not sure the IDP can be made
> to not send them in case they don't.
> Depending on how many Bytes you'll need to save maybe changing to
> "basic" attribute names will bring you back below the threshold?
>
> -peter

-- 
Dr. Martin Haase, Solutions Engineer

DAASI International GmbH        
Europaplatz 3                   
D-72072 Tübingen                
Germany                    

phone: +49 7071 407109-0
fax:   +49 7071 407109-9  
email: martin.haase at daasi.de
web:   www.daasi.de

Sitz der Gesellschaft: Tübingen
Registergericht: Amtsgericht Stuttgart, HRB 382175
Geschäftsleitung: Peter Gietz



More information about the users mailing list