<div dir="ltr">If Iam using a IDP proxy set up, is it possible for me to get the SAML assertion that originated from the real IDP or will I just get the IDP proxy Assertion?</div><div class="gmail_extra"><br clear="all"><div>
<div><br></div><div>--</div>Stefan</div>
<br><br><div class="gmail_quote">On 20 January 2014 15:29, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div class="im">On 1/20/14, 8:32 AM, "Peter Schober" <<a href="mailto:peter.schober@univie.ac.at">peter.schober@univie.ac.at</a>> wrote:<br>
><br>
>Or it just might. Reading the warning section more closely it says<br>
>"the XML is passed along unmodified from the issuer".<br>
<br>
</div>It is, the use case was delegation via a signed assertion.<br>
<br>
It is almost a given that any "back-end" trying to evaluate a standard SSO<br>
assertion is going to be ignoring the SAML standard in validating it,<br>
unless the back-end is simply acting as an agent of the front-end. Web<br>
service delegation with standard SSO tokens is invalid on its face.<br>
<span class="HOEnZb"><font color="#888888"><br>
-- Scott<br>
</font></span><div class="HOEnZb"><div class="h5"><br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br></div>