RE: [saml-dev] SSO Browser profile question

From
Cahill, Conor P <>
Date
2006-06-13T14:28:54+00:00
ID
8AEB79DC01BE994D8DE3FD02FA5B475B03CB5961@orsmsx409
Thread
RE: [saml-dev] SSO Browser profile question
a) SAML provides for relay state information to be passed 
in the authnrequest and returned in the Response.

 

b) The SP can store it's own information in the browser 
(via cookie) prior to sending the user to the IdP and use this information when 
the IdP sends the browser back.

 

Conor

  

  
  From: Goelen, Jurgen 
  [mailto:] 
Sent: Tuesday, June 13, 2006 
  10:24 AM
To: 
Subject: 
  [saml-dev] SSO Browser profile question

  

  

  
Hello *,

  
 

  
Which mechanisms does SAML provide for maintaining the state 
  between the initial resource request of the User Agent and the actual response 
  of the SP? (SSO Browser profile). I will clarify my question with a small example: 

  
 

  
A User Agent accesses a resource on an SP for which it has 
  no security context: 

  
 

  
    
UA requests a resource on the SP. 
    
SP responds with an <AuthnRequest>. (-> no 
    security context) 
    
<AuthnRequest>gets redirected to the IdP. 
    
IdP redirects an assertion about the Principal to the 
    SP. 
    
SP responds to UA. (-> requested 
  resource)

  
 

  
Which SAML mechanisms can be used by an SP to correlate the 
  initial resource request (step 1) with the redirected assertion (step 4)? In 
  other words, how does the SP know which resource it has to provide based on 
  the response of the IdP?

  
 

  
Best 
  regards,

  
 

  
Jurgen 
  Goelen