How to check Issuer existence in idp Response
Michele Innocenti
michele at etruriapa.it
Tue Jul 5 13:47:06 UTC 2022
Il 05/07/22 14:17, Cantor, Scott via users ha scritto:
> On 7/4/22, 4:40 AM, "users on behalf of Michele Innocenti" <users-bounces at shibboleth.net on behalf of michele at etruriapa.it> wrote:
>
>> The only way I could think of to force the presence of the first Issuer
>> element would be to modify the AttributeExtractor to be able to generate
>> an attribute from that element.
> That isn't supported, only the assertion's Issuer can be extracted.
Yes, that's what I understood from the documentation.
>
>> I need to check it to implement SPID authentication.
> The reason doesn't really matter, it isn't supported and it's done for you by the software. If you check the assertion issuer, you've checked the response.
>
> -- Scott
I'm not sure I understand the answer but, like you said, it doesn't matter.
I mentioned Spid just to make you understand why I wanted to do this test.
I should check issuer out of Assertion but I can't because it is expected to be optional.
The problem arises from having non-standard specifications (spid vs saml2).
Thanks anyway.
-- Michele
More information about the users
mailing list