Behavior when skipEndpointValidationWhenSigned is used but ProtocolBinding isn't set

Cantor, Scott cantor.2 at osu.edu
Wed Feb 28 19:00:15 UTC 2024


> Since we're relying on the signed AuthnRequest instead of the
> AssertionConsumerService metadata element, would the missing
> ProtocolBinding explain the failure we're seeing?

Yes.

It's also non-standard behavior, so worth bearing in mind that I don't think anything else supports it (I imagine some don't validate period, but I don't think it's common in SAML to only behave that way with a signature). I use it for a few internal SPs since there's more control but would never count on it in any federated scenario as an SP (if that matters).

-- Scott




More information about the users mailing list