<html>
<head>
<style><!--
.hmmessage P
{
margin:0px;
padding:0px
}
body.hmmessage
{
font-size: 12pt;
font-family:Calibri
}
--></style></head>
<body class='hmmessage'><div dir='ltr'>Thanks Ian, &nbsp;We started the process of updating our metadata in other federations as well to include the SAML2 endpoints just to be on the safer side.<div><br></div><div><br><br><div><div id="SkyDrivePlaceholder"></div><hr id="stopSpelling">Subject: Re: Addition of SAML2 support for SP<br>From: ian@iay.org.uk<br>Date: Thu, 8 Nov 2012 17:02:54 +0000<br>To: users@shibboleth.net<br><br><br><div><div>On 8 Nov 2012, at 16:50, Jayashree Ravi &lt;<a href="mailto:jravi123@hotmail.com">jravi123@hotmail.com</a>&gt; wrote:</div><br class="ecxApple-interchange-newline"><blockquote><div dir="ltr" style="font-family:Calibri;font-size:16px;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;orphans:2;text-align:-webkit-auto;text-indent:0px;text-transform:none;white-space:normal;widows:2;word-spacing:0px"><div style="padding:0px">&lt;SessionInitiator type="Chaining" Location="/Login"</div><div style="padding:0px">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; id="Login" relayState="cookie"&gt;</div><div style="padding:0px">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;SessionInitiator type="Shib1" defaultACSIndex="1" /&gt;&nbsp;&nbsp;</div><div style="padding:0px">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;SessionInitiator type="SAML2" template="bindingTemplate.html" outgoingBindings="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST</div><div style="padding:0px">urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect"&nbsp; /&gt;</div><div style="padding:0px">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;/SessionInitiator&gt;</div></div></blockquote><div><br></div><div>[…]</div><br><blockquote><div dir="ltr" style="font-family:Calibri;font-size:16px;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;orphans:2;text-align:-webkit-auto;text-indent:0px;text-transform:none;white-space:normal;widows:2;word-spacing:0px"><div style="padding:0px">So we are guessing that based on session initiator configuration, it first tries SAML1.1 and if that fails with the IDP it switches to SAML2. […] &nbsp;Since we could not get the answer for this behavior from the documentation we need help in understanding this.</div></div></blockquote><div><br></div><div>Some relevant documentation is here:</div><div><br></div><div><a href="https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPSessionInitiator" target="_blank">https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPSessionInitiator</a></div><div><br></div><div>In particular:</div><div><blockquote><h3 id="ecxNativeSPSessionInitiator-ChainingSessionInitiator" style="padding:0px;font-size:1.4em;font-family:Arial, Helvetica, FreeSans, sans-serif;text-align:left;background-color:rgb(255, 255, 255);z-index:auto">Chaining SessionInitiator</h3><p style="font-size:13px;line-height:17px;color:rgb(51, 51, 51);background-color:rgb(255, 255, 255);padding:0px;margin-bottom:10px;font-family:Arial, Helvetica, FreeSans, sans-serif;text-align:left;z-index:auto">Identified by&nbsp;<code>type="Chaining"</code>, wraps a sequence of&nbsp;<code>SessionInitiator</code>&nbsp;handlers so that they run in series. The series ends when a handler indicates that a response to the browser was returned.</p></blockquote></div><div><br></div><div>So, as you are running the SAML 1 protocol handler first, if it succeeds (if the IdP supports SAML 1 and the handler redirects your client to the IdP) then the SAML 2 protocol handler will not run (as you guessed).</div><div><br></div><blockquote><div dir="ltr" style="font-family:Calibri;font-size:16px;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;orphans:2;text-align:-webkit-auto;text-indent:0px;text-transform:none;white-space:normal;widows:2;word-spacing:0px"><div style="padding:0px">So want to confirm that none of our existing IDP's will fail because of us not registering our SAML2 endpoints with all the existing federations as yet.</div></div></blockquote><div><br></div><div>Probably correct. &nbsp;It's hard to be definitive, though, and minimising the time during which your metadata is different in different places will certainly minimise the chance of problems.</div><div><br></div><div><span class="ecxApple-tab-span" style="font-size:12px;white-space:pre">        </span><span style="font-size:12px">-- Ian</span></div></div><div><span class="ecxApple-style-span" style="border-collapse:separate;border-spacing:0px"><span class="ecxApple-style-span" style="border-collapse:separate;color:rgb(0, 0, 0);font-family:Helvetica;font-size:12px;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing:normal;line-height:normal;orphans:2;text-indent:0px;text-transform:none;white-space:normal;widows:2;word-spacing:0px"><div><span class="ecxApple-style-span" style="font-size:medium"><br></span></div></span></span><br class="ecxApple-interchange-newline">
</div>
<br><br>--
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net</div></div>                                               </div></body>
</html>