IdP integrating with VMWare Horizon as an SP?

Cantor, Scott cantor.2 at osu.edu
Wed Feb 22 00:41:10 UTC 2023


> Are they being unnecessarily picky here or is our metadata not really compliant
> with the specs?

The standard is right here.

https://www.oasis-open.org/committees/download.php/56786/sstc-saml-metadata-errata-2.0-wd-05-diff.pdf

The asbsence of use means the key is designated for all uses.

> Re the SOAP endpoint, I think this is also the first time we've had an SP require
> one.

There is absolutely no chance they do because virtually nobody supports artifacts, certainly nothing commercial for the most part. They're almost certainly wrong. If they require the endpoint when they don't even use the feature, that speaks for itself.

> Is there a way to confirm that we have support for the SOAP artifact resolution
> endpoints enabled (or not disabled, if enabled by default)?

As with all the profiles, that's all controlled by the profile beans turned on in relying-party.xml and all that is documented exhaustively.

Artifact usage requires server state. That isn't something you just turn on. Whether the endpoint or profile is active is not really the issue unless you're not operating a load balanced system.

> And assuming we support them, what should they look like in the metadata?

All the profile endpoints are documented here.

https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1265631857/ProtocolsAndInterfaces

I never got around to finding a better place to lay them out but they're there.

-- Scott




More information about the users mailing list