<div dir="ltr"><div class="gmail_extra"><div class="gmail_quote">On Wed, Jan 27, 2016 at 2:55 PM, Peter Schober <span dir="ltr"><<a href="mailto:peter.schober@univie.ac.at" target="_blank">peter.schober@univie.ac.at</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;padding-left:1ex;border-left-color:rgb(204,204,204);border-left-width:1px;border-left-style:solid">* Antony den Dulk <<a href="mailto:antony@selestiasolutions.com">antony@selestiasolutions.com</a>> [2016-01-27 13:28]:<br></blockquote><div>8< </div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;padding-left:1ex;border-left-color:rgb(204,204,204);border-left-width:1px;border-left-style:solid">
<span>> Seemingly the one of the differences between the 2 methods is that when<br>
> sending an authentication request the 1st method (Shibboleth standard)<br>
> sends the AssertionConsumerServiceURL while the basic does not. The effect<br>
> of the 2nd method is that the Metadata is used to determine the<br>
> AssertionConsumerServiceURL allowing the setup of various reverse-proxy<br>
> scenaries.<br>
<br>
</span>The downside of not sending the endpoint being that (unless the authn<br>
request is signed) the IDP has no chance to verify that the location it<br>
should send the response to is legit and belongs to the SP in question<br>
(as Issuer of the request). Such a check is not optional according to<br>
the spec, IIRC.<br></blockquote><div> </div><div>The Authentication Request is signed.</div><div> </div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;padding-left:1ex;border-left-color:rgb(204,204,204);border-left-width:1px;border-left-style:solid">
<span><br>
> I have heard from another person that there is a way to arrange this in<br>
> Shibboleth but they do not have details on how.<br>
<br>
</span>The question is why change the Shib SP from providing legal and useful<br>
(if not signing: required) information?<br>
If the IDP does not support valid auth requests it has a bug.</blockquote><div> </div><div>The reason not to send the information is so the Metadata becomes leading in determining endpoints. The IdP supports both methods of Authentication Requests - they (the IdP developers) claim that both methods are in the SAML 2.0 spec (see <a href="https://docs.oasis-open.org/security/saml/v2.0/saml-core-2.0-os.pdf">https://docs.oasis-open.org/security/saml/v2.0/saml-core-2.0-os.pdf</a> @ page 59 row 2061) and that an SP that does not support both is not implementing the spec properly (in their opinion).</div><div> </div><div>Thanks for taking the time to answer,</div><div>Antony</div></div><br></div></div>