do not checkAddress in idp-proxy situation for private IPs

Jehan PROCACCIA jehan.procaccia at tem-tsp.eu
Mon Mar 8 20:01:45 UTC 2021


indeed ! 
so should I apply the setting in the DefaultRelyingParty ? 

 <bean id="shibboleth.DefaultRelyingParty" parent="RelyingParty" >
 <property name="profileConfigurations">
            <list>
            <bean parent="SAML2.SSO" p:postAuthenticationFlows="attribute-release" p:checkAddress="false" />

----- Mail original -----
De: "Cantor, Scott" <cantor.2 at osu.edu>
À: "users" <users at shibboleth.net>
Envoyé: Lundi 8 Mars 2021 20:44:59
Objet: Re: do not checkAddress in idp-proxy situation for private IPs

On 3/8/21, 2:41 PM, "users on behalf of Jehan PROCACCIA" <users-bounces at shibboleth.net on behalf of jehan.procaccia at tem-tsp.eu> wrote:

>    so I've set it in relying-party.xml for our docusign entityIds (we have a prod and dev instances) 

That would imply Docusign is the IdP. This setting doesn't apply to SPs.

-- Scott


-- 
For Consortium Member technical support, see https://wiki.shibboleth.net/confluence/x/coFAAg
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list