← Prev in month
← Prev in thread
Errors with HTTP redirect Binding
Specifications for redirect binding says : "HTTP interactions during the message exchange MUST NOT use HTTP error status codes to indicate failures in SAML processing, since the user agent is not a full party to the SAML protocol exchange." If a SP receive a request with this binding and the URI indicated in the issuer element of the request is unknown, the SP can't guess the URL of the sender and then, can't send any response to it. So the only way is to send an HTTP error status... Is it a contradiction with preceding "MUST NOT" ? Val廨ie
← Prev in month
← Prev in thread