<div dir="ltr"><blockquote style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex" class="gmail_quote">There is always an explicit request.</blockquote><div class="gmail_default" style="font-family:trebuchet ms,sans-serif;font-size:small;color:#073763"><br></div><div class="gmail_default" style="font-family:trebuchet ms,sans-serif;font-size:small;color:#073763">Quibble.  There is no SAML stanza "samlp:AuthnRequest" being received by the IdP unless the IdP itself is generating it.  There certainly isn't anything being provided by my browser like what would be redirected through the browser for an SP-initiated session.</div><div class="gmail_default" style="font-family:trebuchet ms,sans-serif;font-size:small;color:#073763"><br></div><div class="gmail_default" style="font-family:trebuchet ms,sans-serif;font-size:small;color:#073763">Your point is well taken, though.  Thanks for framing it in a way that will make it easier to explain to the vendor.</div><div class="gmail_default" style="font-family:trebuchet ms,sans-serif;font-size:small;color:#073763"><br></div><div class="gmail_default" style="font-family:trebuchet ms,sans-serif;font-size:small;color:#073763">-L</div><div><div dir="ltr" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><br><hr style="color:rgb(0,0,0);font-family:"times new roman","new york",times,serif;font-size:16px"><div style="color:rgb(0,0,0);font-family:"times new roman","new york",times,serif;font-size:16px;text-align:right"><span size="2" style="color:rgb(153,102,51);font-size:small">Les LaCroix '79 </span><span style="color:rgb(153,102,51)">|</span><span size="2" style="color:rgb(153,102,51);font-size:small"> </span><span size="2" style="color:rgb(153,102,51);font-size:small">Strategic Technologist<br></span><span size="2" style="color:rgb(153,102,51);font-size:small">Carleton College </span><span style="color:rgb(153,102,51)">|</span><span size="2" style="color:rgb(153,102,51);font-size:small"> 1 N. College St. </span><span style="color:rgb(153,102,51)">|</span><span size="2" style="color:rgb(153,102,51);font-size:small"> MS 3-ITS </span><span style="color:rgb(153,102,51)">|</span><span size="2" style="color:rgb(153,102,51);font-size:small"> Northfield, MN 55057<br></span><span size="2" style="color:rgb(153,102,51);font-size:small">507.222.5455</span></div></div></div></div></div></div></div></div></div></div></div></div></div></div><br></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Tue, Oct 22, 2019 at 11:03 AM Cantor, Scott <<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">On 10/22/19, 11:46 AM, "users on behalf of Les LaCroix" <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:llacroix@carleton.edu" target="_blank">llacroix@carleton.edu</a>> wrote:<br>
<br>
> Since there isn't any interaction with the SP, does that mean that AuthnRequestsSigned="true" in SP metadata and <br>
> unsolicited SSO are mutually exclusive? <br>
<br>
Yes.<br>
<br>
> Is there any place I can point the vendor to that says AuthnRequestsSigned must be "false" for unsolicited SSO so they<br>
> will fix their metadata?<br>
<br>
Not if common sense isn't sufficient.<br>
<br>
> On the other hand, there isn't any explicit authnRequest being sent.<br>
<br>
There is always an explicit request. Failure to enforce the flag would mean the flag meant nothing since any attacker would simply bypass the normal flow and issue an unsigned redirect to get around the policy the flag is trying to impose.<br>
<br>
> I can change my local copy of the metadata to say AuthnRequestsSigned="false", and that's what I'm doing while I try<br>
> to convince them to change it at the source.  It's a problem lying in wait if we ever have to update their metadata,<br>
> though.<br>
<br>
If the metadata is unsigned, or doesn't have a proper sliding validity window, or isn't being resigned frequently, then it is inherently a problem to rely on it since it breaks the security model of the system, so the problem is largely moot in practice.<br>
<br>
-- Scott<br>
<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>