<div dir="ltr">We ask that exact question a lot as it tends to get more &quot;yes&quot; answers out of vendors who may support SAML but for some odd reason have never heard of Shibboleth.  As your an SP, I wouldn&#39;t read too deeply into the question.  Tell them you&#39;re running the Shibboleth SP 2.5 and inquire about what type of IdP they&#39;re trying to bring to the table.  After that, then worry about profiles and bindings.<div>
<br></div><div><div>Dave</div></div></div><div class="gmail_extra"><br><br><div class="gmail_quote">On Tue, May 28, 2013 at 2:52 PM, Cantor, Scott <span dir="ltr">&lt;<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>&gt;</span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div class="im">On 5/28/13 4:38 PM, &quot;MikeWho&quot; &lt;<a href="mailto:who@me.com">who@me.com</a>&gt; wrote:<br>
<br>
&gt;During an integration discussion with a client, we were asked if our<br>
&gt;application (i.e. site) is &quot;SAML 2.0 compliant&quot;. Is there a specific<br>
&gt;definition of/criteria for this? Do all 2.0 bindings need to be supported,<br>
&gt;or just any one?<br>
<br>
</div>There is nothing in SAML conformance that addresses *deployments*, so this<br>
isn&#39;t a valid question, though it is a common one. What people usually<br>
mean is whether you have a deployment that uses an implementation of SAML<br>
that is itself generally conformant and won&#39;t be riddled with limitations.<br>
But you can use a conformant product and just pick all the worst options<br>
or impose the worst approaches, and it will be just as bad (not that you<br>
are, just making a point).<br>
<br>
The closest thing to a vanilla *deployment* profile that we have is<br>
saml2int (see <a href="http://saml2int.org" target="_blank">saml2int.org</a>). That is something a deployment can claim to<br>
support and addresses your other question, I think.<br>
<div class="im"><br>
&gt;Instead of a yes/no answer, I guess I&#39;ll have to go with &quot;well, we are<br>
&gt;using<br>
&gt;Shibboleth 2.5 SP to implement SP initiated SSO with HTTP Redirect<br>
&gt;binding;<br>
&gt;and support just-in-time user provisioning.&quot; But I don&#39;t know if that&#39;s a<br>
&gt;yes, no or maybe.<br>
<br>
</div>That&#39;s pretty much a yes, but note that you described there the outgoing<br>
binding (SP to IdP) and not the inbound one.<br>
<br>
But it&#39;s often an implication, for example, that you&#39;re handling metadata<br>
&quot;well&quot;, by virtue of using the only implementation in the world that does.<br>
In large respect, that fact alone is more important than most of the other<br>
SAML requirements you could try and enumerate, and it isn&#39;t captured<br>
anywhere in SAML 2.0&#39;s original, long outdated, conformance material.<br>
<span class="HOEnZb"><font color="#888888"><br>
-- Scott<br>
</font></span><div class="HOEnZb"><div class="h5"><br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br><br clear="all"><div><br></div>-- <br>David Langenberg<div>Identity &amp; Access Management</div><div>The University of Chicago</div>
</div>