How to configure IdP with zero info from SP ?

Cantor, Scott cantor.2 at osu.edu
Fri Mar 3 18:34:21 UTC 2023


You can set ignoreRequestSignatures to bypass that step and get far enough to reverse engineer the rest; whether you leave it that way is your decision.

I would likely not trust such an SP to manage their key properly anyway, so bypassing it is not out of the question.

Of course the red flag is that an SP this incompetent is likely not trustworthy enough to believe they even validate SSO properly either.

-- Scott





More information about the users mailing list