<div dir="ltr"><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">Yes, because if you don't and an SP requests that protocol binding, your IdP will respond on the assumption the SP will be able to make its callback and your metadata will prevent that.</blockquote><div>Thanks, that helps a lot but I worry I may still have a misconfiguration / misunderstanding.</div><div><br></div><div><a href="https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1265631690/SAML2ArtifactResolutionConfiguration" target="_blank">https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1265631690/SAML2ArtifactResolutionConfiguration</a> recommends to disable the SAML2.ArtifactResolution profile configuration bean if not in use. On this basis, I was planning to remove that bean from our relying party config and now know that I should also set idp.artifact.enabled = false. I've already removed the ArtifactResolutionService endpoint from our metadata, which may have been premature. With all these changes in place, do I need to do anything else to disable/prevent use of the Artifact profile with Browser SSO?</div><div><br></div><div>Regards,</div><div><br></div><div>Max </div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Tue, 26 Sept 2023 at 17:24, Cantor, Scott <<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">> As we don't advertise support for the ArtifactResolutionService does that<br>
> mean we should also set idp.artifact.enabled = false?<br>
<br>
Yes, because if you don't and an SP requests that protocol binding, your IdP will respond on the assumption the SP will be able to make its callback and your metadata will prevent that.<br>
<br>
I was simply saying that tearing down an extra port/connector has nothing to do with whether you support SOAP-based profiles. Nobody needs an extra port anymore, regardless.<br>
<br>
-- Scott<br>
<br>
<br>
</blockquote></div><div><br></div></div>