<html>
<head>
<style><!--
.hmmessage P
{
margin:0px;
padding:0px
}
body.hmmessage
{
font-size: 12pt;
font-family:Calibri
}
--></style></head>
<body class='hmmessage'><div dir='ltr'>Thanks Ian, We started the process of updating our metadata in other federations as well to include the SAML2 endpoints just to be on the safer side.<div><br></div><div><br><br><div><div id="SkyDrivePlaceholder"></div><hr id="stopSpelling">Subject: Re: Addition of SAML2 support for SP<br>From: ian@iay.org.uk<br>Date: Thu, 8 Nov 2012 17:02:54 +0000<br>To: users@shibboleth.net<br><br><br><div><div>On 8 Nov 2012, at 16:50, Jayashree Ravi <<a href="mailto:jravi123@hotmail.com">jravi123@hotmail.com</a>> wrote:</div><br class="ecxApple-interchange-newline"><blockquote><div dir="ltr" style="font-family:Calibri;font-size:16px;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;orphans:2;text-align:-webkit-auto;text-indent:0px;text-transform:none;white-space:normal;widows:2;word-spacing:0px"><div style="padding:0px"><SessionInitiator type="Chaining" Location="/Login"</div><div style="padding:0px"> id="Login" relayState="cookie"></div><div style="padding:0px"> <SessionInitiator type="Shib1" defaultACSIndex="1" /> </div><div style="padding:0px"> <SessionInitiator type="SAML2" template="bindingTemplate.html" outgoingBindings="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST</div><div style="padding:0px">urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" /></div><div style="padding:0px"> </SessionInitiator></div></div></blockquote><div><br></div><div>[…]</div><br><blockquote><div dir="ltr" style="font-family:Calibri;font-size:16px;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;orphans:2;text-align:-webkit-auto;text-indent:0px;text-transform:none;white-space:normal;widows:2;word-spacing:0px"><div style="padding:0px">So we are guessing that based on session initiator configuration, it first tries SAML1.1 and if that fails with the IDP it switches to SAML2. […] Since we could not get the answer for this behavior from the documentation we need help in understanding this.</div></div></blockquote><div><br></div><div>Some relevant documentation is here:</div><div><br></div><div><a href="https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPSessionInitiator" target="_blank">https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPSessionInitiator</a></div><div><br></div><div>In particular:</div><div><blockquote><h3 id="ecxNativeSPSessionInitiator-ChainingSessionInitiator" style="padding:0px;font-size:1.4em;font-family:Arial, Helvetica, FreeSans, sans-serif;text-align:left;background-color:rgb(255, 255, 255);z-index:auto">Chaining SessionInitiator</h3><p style="font-size:13px;line-height:17px;color:rgb(51, 51, 51);background-color:rgb(255, 255, 255);padding:0px;margin-bottom:10px;font-family:Arial, Helvetica, FreeSans, sans-serif;text-align:left;z-index:auto">Identified by <code>type="Chaining"</code>, wraps a sequence of <code>SessionInitiator</code> handlers so that they run in series. The series ends when a handler indicates that a response to the browser was returned.</p></blockquote></div><div><br></div><div>So, as you are running the SAML 1 protocol handler first, if it succeeds (if the IdP supports SAML 1 and the handler redirects your client to the IdP) then the SAML 2 protocol handler will not run (as you guessed).</div><div><br></div><blockquote><div dir="ltr" style="font-family:Calibri;font-size:16px;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;orphans:2;text-align:-webkit-auto;text-indent:0px;text-transform:none;white-space:normal;widows:2;word-spacing:0px"><div style="padding:0px">So want to confirm that none of our existing IDP's will fail because of us not registering our SAML2 endpoints with all the existing federations as yet.</div></div></blockquote><div><br></div><div>Probably correct. It's hard to be definitive, though, and minimising the time during which your metadata is different in different places will certainly minimise the chance of problems.</div><div><br></div><div><span class="ecxApple-tab-span" style="font-size:12px;white-space:pre">        </span><span style="font-size:12px">-- Ian</span></div></div><div><span class="ecxApple-style-span" style="border-collapse:separate;border-spacing:0px"><span class="ecxApple-style-span" style="border-collapse:separate;color:rgb(0, 0, 0);font-family:Helvetica;font-size:12px;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;orphans:2;text-indent:0px;text-transform:none;white-space:normal;widows:2;word-spacing:0px"><div><span class="ecxApple-style-span" style="font-size:medium"><br></span></div></span></span><br class="ecxApple-interchange-newline">
</div>
<br><br>--
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net</div></div>                                            </div></body>
</html>