<html><head><meta http-equiv="Content-Type" content="text/html charset=windows-1252"><base href="x-msg://1640/"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><br><div><div>On 8 Nov 2012, at 16:50, Jayashree Ravi &lt;<a href="mailto:jravi123@hotmail.com">jravi123@hotmail.com</a>&gt; wrote:</div><br class="Apple-interchange-newline"><blockquote type="cite"><div dir="ltr" style="font-family: Calibri; font-size: 16px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; "><div style="margin: 0px; padding: 0px; ">&lt;SessionInitiator type="Chaining" Location="/Login"</div><div style="margin: 0px; padding: 0px; ">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; id="Login" relayState="cookie"&gt;</div><div style="margin: 0px; padding: 0px; ">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;SessionInitiator type="Shib1" defaultACSIndex="1" /&gt;&nbsp;&nbsp;</div><div style="margin: 0px; padding: 0px; ">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;SessionInitiator type="SAML2" template="bindingTemplate.html" outgoingBindings="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST</div><div style="margin: 0px; padding: 0px; ">urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect"&nbsp; /&gt;</div><div style="margin: 0px; padding: 0px; ">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &lt;/SessionInitiator&gt;</div></div></blockquote><div><br></div><div>[…]</div><br><blockquote type="cite"><div dir="ltr" style="font-family: Calibri; font-size: 16px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; "><div style="margin: 0px; padding: 0px; ">So we are guessing that based on session initiator configuration, it first tries SAML1.1 and if that fails with the IDP it switches to SAML2. […] &nbsp;Since we could not get the answer for this behavior from the documentation we need help in understanding this.</div></div></blockquote><div><br></div><div>Some relevant documentation is here:</div><div><br></div><div><a href="https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPSessionInitiator">https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPSessionInitiator</a></div><div><br></div><div>In particular:</div><div><blockquote type="cite"><h3 id="NativeSPSessionInitiator-ChainingSessionInitiator" style="padding: 0px; font-size: 1.4em; margin: 1.5em 0px 0.5em; font-family: Arial, Helvetica, FreeSans, sans-serif; text-align: left; background-color: rgb(255, 255, 255); position: static; z-index: auto; ">Chaining SessionInitiator</h3><p style="font-size: 13px; line-height: 17px; color: rgb(51, 51, 51); background-color: rgb(255, 255, 255); padding: 0px; margin-bottom: 10px; font-family: Arial, Helvetica, FreeSans, sans-serif; text-align: left; position: static; z-index: auto; ">Identified by&nbsp;<code>type="Chaining"</code>, wraps a sequence of&nbsp;<code>SessionInitiator</code>&nbsp;handlers so that they run in series. The series ends when a handler indicates that a response to the browser was returned.</p></blockquote></div><div><br></div><div>So, as you are running the SAML 1 protocol handler first, if it succeeds (if the IdP supports SAML 1 and the handler redirects your client to the IdP) then the SAML 2 protocol handler will not run (as you guessed).</div><div><br></div><blockquote type="cite"><div dir="ltr" style="font-family: Calibri; font-size: 16px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; "><div style="margin: 0px; padding: 0px; ">So want to confirm that none of our existing IDP's will fail because of us not registering our SAML2 endpoints with all the existing federations as yet.</div></div></blockquote><div><br></div><div>Probably correct. &nbsp;It's hard to be definitive, though, and minimising the time during which your metadata is different in different places will certainly minimise the chance of problems.</div><div><br></div><div><span class="Apple-tab-span" style="font-size: 12px; white-space: pre; ">        </span><span style="font-size: 12px; ">-- Ian</span></div></div><div apple-content-edited="true"><span class="Apple-style-span" style="border-collapse: separate; border-spacing: 0px; "><span class="Apple-style-span" style="border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; "><div><span class="Apple-style-span" style="font-size: medium; "><br></span></div></span></span><br class="Apple-interchange-newline">
</div>
<br></body></html>