<div dir="ltr">Thanks Nate -- succinct and much appreciated!<br></div><div class="gmail_extra"><br><div class="gmail_quote">On Fri, Jun 3, 2016 at 8:58 PM, Nate Klingenstein <span dir="ltr"><<a href="mailto:ndk@sudonym.me" target="_blank">ndk@sudonym.me</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div style="word-wrap:break-word">Jann,<div><br></div><div>There’s the technical answer, and there’s the philosophical answer.</div><div><br></div><div>Philosophically, it was decided to use a separate port for TLS-secured and -mutually-authenticated communications between the IdP and the SP to enable usage of client-facing credentials on 443 without forcing their use in federated transactions.</div><div><br></div><div>This is how early versions of Shibboleth worked, and many SSO protocols still work this way.  There are serious deployment burden downsides to the use of the back channel, but there are also very important use cases that it makes possible.</div><div><br></div><div>That specific binding advertises that your IdP is ready, willing and able to answer SAML 2.0 AttributeQuery requests issued directly by SP’s to that endpoint.  Whether that’s true or not gets into the wiring you have behind it.  The only firm recommendation is that your metadata must accurately represent the capabilities of your IdP.</div><div><br></div><div>For further exhumation:</div><div><br></div><div><a href="https://spaces.internet2.edu/pages/viewpage.action?pageId=98306418#IdentityProviderDiscussionTopics(IdPv3)-8.TheBackChannelKoan" target="_blank">https://spaces.internet2.edu/pages/viewpage.action?pageId=98306418#IdentityProviderDiscussionTopics(IdPv3)-8.TheBackChannelKoan</a></div><div><br></div><div>Take care,</div><div>Nate.</div><div><br><div><div><blockquote type="cite"><div><div class="h5"><div>On Jun 3, 2016, at 21:30, Jann Malenkoff <<a href="mailto:jannmalenkoff@gmail.com" target="_blank">jannmalenkoff@gmail.com</a>> wrote:</div><br></div></div><div><div><div class="h5"><div dir="ltr"><div><div>There is a bit of a debate going on at or university.<br><br></div>What exactly is the following used for by the IdP?<br><br></div>If we use SAML2 - what is the purpose of the back-channel port 8443?<br><div><div><div><br><AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP"<br>                          Location="<a href="https://example.edu:8443/idp/profile/SAML2/SOAP/AttributeQuery" target="_blank">https://example.edu:8443/idp/profile/SAML2/SOAP/AttributeQuery</a>" /><br></div></div></div></div></div></div><span class="HOEnZb"><font color="#888888">
-- <br>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a></font></span></div></blockquote></div><br></div></div></div><br>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br></blockquote></div><br></div>