<div dir="ltr"><br><div class="gmail_extra"><br><div class="gmail_quote">On Fri, Dec 16, 2016 at 11:33 AM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">On 12/16/16, 11:26 AM, "users on behalf of Br LRd" <<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:blasterradius@gmail.com">blasterradius@gmail.com</a>> wrote:<br>
<br>
> Reason I don't want to use http post is that my client can't do HTTP responses so a POST redirect wouldn't work.<br>
<br>
Then you shouldn't be using the Browser SSO profile, that's a fairly explicit piece of advice I can give you.<br>
<br>
Contrary to Scott's assumption, I think ECP and PAOS is in fact what you should be using. If your client is not a browser, you MUST use ECP.<br>
<br></blockquote><div><br></div><div>Yes, sorry, I was assuming the use of a standard web browser client.</div><div><br></div><div>If you are building a non-web browser client then ECP and the PAOS binding is as Scott C indicates the approach to use.</div><div><br></div><div>Thanks,</div><div><br></div><div>Scott K </div></div></div></div>