<div dir="ltr">Thanks Peter, It is clear now :)</div><div class="gmail_extra"><br><div class="gmail_quote">On Mon, Sep 11, 2017 at 5:33 AM, Peter Schober <span dir="ltr"><<a href="mailto:peter.schober@univie.ac.at" target="_blank">peter.schober@univie.ac.at</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">* Satheesh Kumar <<a href="mailto:satheeshvsbk@gmail.com">satheeshvsbk@gmail.com</a>> [2017-09-11 11:19]:<br>
<span class="">>      We have SP 2.6 and when sending <authnrequest> to one of our<br>
> registered IDP, the attributes like "TARGET", "RelayState", "SAMLRequest",<br>
> "SAMLResponse", "SAMLart", "SigAlg"  are encoded within a form as hidden<br>
> fields in "bindingTemplate.html" and the form is submitted along with authn<br>
> request. This is happening only for specific IDP's and I am not sure why<br>
> this is happening.<br>
<br>
</span>That's used when the SAML 2.0 Authentication Request (note the<br>
html/head/title of the bindingTemplate.html) needs to be sent to the<br>
IDP using the HTTP-POST protocol binding.<br>
<br>
Other IDPs may recieve authentication requests using the HTTP-Redirect<br>
protocol binding.<br>
<br>
You can find the details of those bindings in the SAML Bindings spec, e.g.:<br>
<a href="https://www.oasis-open.org/committees/download.php/56779/sstc-saml-bindings-errata-2.0-wd-06.pdf" rel="noreferrer" target="_blank">https://www.oasis-open.org/<wbr>committees/download.php/56779/<wbr>sstc-saml-bindings-errata-2.0-<wbr>wd-06.pdf</a><br>
<br>
As to *why* the SP uses HTTP-POST one time and HTTP-Redirect another:<br>
That depends on the bindings the IDP publishes in its SAML 2.0<br>
Metadata.  The IDP recieving requests via HTTP-POST will likely only<br>
announce support for HTTP-POST in its SingleSignOnService element.<br>
<span class="HOEnZb"><font color="#888888"><br>
-peter<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br>
</font></span></blockquote></div><br><br clear="all"><div><br></div>-- <br><div class="gmail_signature" data-smartmail="gmail_signature">*Best wishes*,<br>*Satheesh K*<br><br><br><br></div>
</div>