<html><head></head><body bgcolor="#FFFFFF"><div>Thanks again Peter and Scott ; that was very helpful<br><br>Sent from my iPhone</div><div><br>On Oct 2, 2012, at 6:13 AM, C G </div><div>wrote:<br><br></div><div></div><blockquote type="cite"><div><div style="color:#000; background-color:#fff; font-family:times new roman, new york, times, serif;font-size:12pt"><div>Probably this is a basic Q (and for my part did some reading/homework).</div><div>Wanted to confirm if this is a good control flow (among several possible) as per my understanding.</div><div>I am interested in the following scenerio (IDP --> Shib Id provider, SP service provider/RP relying party)</div><div><br></div><div>0. If user comes directly to IDP, it redirects to SP/RP<br></div><div style="color: rgb(0, 0, 0); font-size: 16px; font-family: 'times new roman', 'new york', times, serif; background-color: transparent; font-style: normal; ">1. User goes to SP/RP </div><div style="color: rgb(0, 0, 0); font-size: 16px; font-family: 'times new roman', 'new york', times, serif; background-color: transparent; font-style: normal; ">2. SP/RP sends user to IDP</div><div style="color: rgb(0, 0, 0); font-size: 16px;
font-family: 'times new roman', 'new york', times, serif; background-color: transparent; font-style: normal; ">3. IDP asks user to enter _Userid_ and _Password_</div><div style="color: rgb(0, 0, 0); font-size: 16px; font-family: 'times new roman', 'new york', times, serif; background-color: transparent; font-style: normal; ">4. IDP authenticates and asserts via SAML the _Userid_ in step3 </div><div style="color: rgb(0, 0, 0); font-size: 16px; font-family: 'times new roman', 'new york', times, serif; background-color: transparent; font-style: normal; ">5. IDP redirects user back to SP/RP</div><div style="color: rgb(0, 0, 0); font-size: 16px; font-family: 'times new roman', 'new york', times, serif; background-color: transparent; font-style: normal; ">6. SP/RP based on the asserted _Userid_ will open up services</div><div style="color: rgb(0, 0, 0); font-size: 16px; font-family: 'times new roman', 'new york', times, serif; background-color:
transparent; font-style: normal; "><br></div><div style="color: rgb(0, 0, 0); font-size: 16px; font-family: 'times new roman', 'new york', times, serif; background-color: transparent; font-style: normal; "><br></div><div style="color: rgb(0, 0, 0); font-size: 16px; font-family: 'times new roman', 'new york', times, serif; background-color: transparent; font-style: normal; ">For the Shib-IDP part, does it set any cookie before redirecting?</div><div style="color: rgb(0, 0, 0); font-size: 16px; font-family: 'times new roman', 'new york', times, serif; background-color: transparent; font-style: normal; ">How does SP/RP makes sure that userid that is authenticated is indeed the one to allow access to services?</div><div style="color: rgb(0, 0, 0); font-size: 16px; font-family: 'times new roman', 'new york', times, serif; background-color: transparent; font-style: normal; ">specifically how does provision for man-in-middle attack is addressed? (example
flip user-id or stole cookie if there is one)</div><div style="color: rgb(0, 0, 0); font-size: 16px; font-family: 'times new roman', 'new york', times, serif; background-color: transparent; font-style: normal; "><br></div><div style="color: rgb(0, 0, 0); font-size: 16px; font-family: 'times new roman', 'new york', times, serif; background-color: transparent; font-style: normal; ">many thanks in advance for your pointers </div></div></div></blockquote></body></html>