Behavior when skipEndpointValidationWhenSigned is used but ProtocolBinding isn't set
Cantor, Scott
cantor.2 at osu.edu
Wed Feb 28 19:00:15 UTC 2024
> Since we're relying on the signed AuthnRequest instead of the
> AssertionConsumerService metadata element, would the missing
> ProtocolBinding explain the failure we're seeing?
Yes.
It's also non-standard behavior, so worth bearing in mind that I don't think anything else supports it (I imagine some don't validate period, but I don't think it's common in SAML to only behave that way with a signature). I use it for a few internal SPs since there's more control but would never count on it in any federated scenario as an SP (if that matters).
-- Scott
More information about the users
mailing list