IdP v4 saml response size
Martin Haase
Martin.Haase at DAASI.de
Fri Mar 5 11:31:52 UTC 2021
Thanks Peter,
encryption... the obvious. We'll give it a try. At least until this SP
will be have been fixed.
Cheers
Martin
Am 05.03.21 um 11:25 schrieb Peter Schober:
> * Martin Haase <Martin.Haase at DAASI.de> [2021-03-05 08:53]:
>> Regarding attributes, there is no option to send less. Any other
>> ideas?
> Well, what is it about IDPv4 that made the response bigger?
>
> Not signing certainly certainly isn't an option (though maybe moving
> the signaure elsewhere, if Response then sign the Assertion or vice
> versa) avoids this?
>
> Not encrypting (as that should also include the cert the IDP
> encrytpted it to) and relying on TLS only might be acceptable and
> probably has the largest potential for size reduction.
>
> Use the backchannel (attribute queries, artifacts)?
> Using the HTTP-POST-SimpleSign protocol binding might also change this
> a bit but if they support that they'd very likely be running a
> Shibboleth SP and that has no issues with response sizes to begin
> with.
>
> Do they look at the NameID? If not maybe not sending one makes a difference.
> Do they check NameFormats of attributes? Not sure the IDP can be made
> to not send them in case they don't.
> Depending on how many Bytes you'll need to save maybe changing to
> "basic" attribute names will bring you back below the threshold?
>
> -peter
--
Dr. Martin Haase, Solutions Engineer
DAASI International GmbH
Europaplatz 3
D-72072 Tübingen
Germany
phone: +49 7071 407109-0
fax: +49 7071 407109-9
email: martin.haase at daasi.de
web: www.daasi.de
Sitz der Gesellschaft: Tübingen
Registergericht: Amtsgericht Stuttgart, HRB 382175
Geschäftsleitung: Peter Gietz
More information about the users
mailing list