Login target url parameter limit
Pavel Šipoš
pavel.sipos at arnes.si
Mon Feb 20 14:14:04 UTC 2023
DS is redirecting user back to the SP with idp entityid set, but it
takes that target url as the SP endpoint and not the SP url from metadata.
Pavel
On 20/02/2023 14:48, Peter Schober via users wrote:
> * Pavel Šipoš <pavel.sipos at arnes.si> [2023-02-20 14:28]:
>> It is actually our DS that is making redirection and not shibboleth
>> SP (I checked that now with samltracer).
> That shouldn't be the case with SAML 2.0, it's always the SP making
> that final redirect to the IDP: The SP might want to sign the
> authnRequest or put other info into it.
>
>> As we use simplesamlphp for DS I will have to look for answer there.
> First make sure you're using SAML 2.0 and not the old "WAYF" protocol
> that forces usage of SAML1.
>
> -peter
--
--
Pavel Sipos, Arnes <pavel.sipos at arnes.si>
ARNES, p.p. 7, SI-1001 Ljubljana, Slovenia
T: +386 1 479 88 00
W: www.arnes.si, aai.arnes.si
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 5772 bytes
Desc: S/MIME Cryptographic Signature
URL: <http://shibboleth.net/pipermail/users/attachments/20230220/c9aed92c/attachment.p7s>
More information about the users
mailing list