<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=Windows-1252">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; ">
<div>I can't speak to #1, but #2 is what the software does by default if the metadata and AuthnRequest are written right.</div>
<div><br>
</div>
<div>e.g. from&nbsp;<a href="http://testshib.org/metadata/testshib-providers.xml">http://testshib.org/metadata/testshib-providers.xml</a></div>
<div><br>
</div>
<div>&lt;AssertionConsumerService index=&quot;1&quot; isDefault=&quot;true&quot; Binding=&quot;urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST&quot; Location=&quot;<a href="https://sp.testshib.org/Shibboleth.sso/SAML2/POST">https://sp.testshib.org/Shibboleth.sso/SAML2/POST</a>&quot;/&gt;</div>
<div><br>
</div>
<div>and the AuthnRequest(note the AssertionConsumerServiceURL and the ProtocolBinding):</div>
<div><br>
</div>
<div>&lt;samlp:AuthnRequest xmlns:samlp=&quot;urn:oasis:names:tc:SAML:2.0:protocol&quot; AssertionConsumerServiceURL=&quot;<a href="https://sp.testshib.org/Shibboleth.sso/SAML2/POST">https://sp.testshib.org/Shibboleth.sso/SAML2/POST</a>&quot; Destination=&quot;<a href="https://idp.testshib.org/idp/profile/SAML2/Redirect/SSO">https://idp.testshib.org/idp/profile/SAML2/Redirect/SSO</a>&quot;
 ID=&quot;_1a29a54e828c6c52a6c1f86bff6fff7b&quot; IssueInstant=&quot;2013-05-31T16:13:38Z&quot; ProtocolBinding=&quot;urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST&quot; Version=&quot;2.0&quot;&gt;&lt;saml:Issuer xmlns:saml=&quot;urn:oasis:names:tc:SAML:2.0:assertion&quot;&gt;<a href="https://sp.testshib.org/shibboleth-sp&lt;/saml:Issuer&gt;">https://sp.testshib.org/shibboleth-sp&lt;/saml:Issuer&gt;</a>&lt;samlp:NameIDPolicy
 AllowCreate=&quot;1&quot;/&gt;&lt;/samlp:AuthnRequest&gt;</div>
<div><br>
</div>
<div>If they know enough to make that request, I hope they know enough to formulate good metadata and AuthnRequests.</div>
<br>
<div>
<div>On May 31, 2013, at 16:06 , Nickles, Brent wrote:</div>
<br class="Apple-interchange-newline">
<blockquote type="cite">
<div style="margin-top: 0in; margin-right: 0in; margin-left: 0.5in; margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; text-indent: -0.25in; ">
<span>2.<span style="font: normal normal normal 7pt/normal 'Times New Roman'; ">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<span class="Apple-converted-space">&nbsp;</span></span></span>They support SAML but the only consume assertions to a specific location.&nbsp;&nbsp; They are expecting us to send a SAML
 response via an HTTP-POST to specific location….how is this done?<o:p></o:p></div>
<br class="Apple-interchange-newline">
</blockquote>
</div>
<br>
</body>
</html>