<p dir="ltr">While I understand your argument, it goes counter to most other SAML products. Adfs, openam, oif, ping, etc all work this way. Also you aren&#39;t circumventing signing the authn request you are kicking off authentication directly from the idp so its not exactly the same thing. </p>
<p dir="ltr">Thanks<br>
Marc</p>
<div class="gmail_quote">On Mar 15, 2015 1:23 PM, &quot;Cantor, Scott&quot; &lt;<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>&gt; wrote:<br type="attribution"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">On 3/15/15, 12:00 PM, &quot;Marc Boorshtein&quot; &lt;<a href="mailto:mboorshtein@gmail.com">mboorshtein@gmail.com</a>&gt; wrote:<br>
<br>
&gt;It looks like the idp is looking for an authnrequest even though one doesn&#39;t exist.  Is this a bug?<br>
<br>
That&#39;s debateable. I don&#39;t know what V2 did/does in this case, but even if it &quot;works&quot;, I could make a pretty strong case that the V2 behavior is the bug. I don&#39;t think I&#39;m inclined to change this. If the metadata says the SP signs its requests, you shouldn&#39;t be able to circumvent that, it would make the feature worthless.<br>
<br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>