← Prev in month ← Prev in thread

supporting the AuthnRequest protocol

From
Tom Scavo <>
Date
2013-03-17T19:15:11+00:00
ID
CAEtu=dNXyUB48rDtrDhusg3fzug5=54G2fuGRofknDyxhoC=
Thread
supporting the AuthnRequest protocol
As you know, the SAML2 Web Browser SSO Profile calls out the use of
the AuthnRequest protocol to support SP-initiated SSO [SAML2Prof,
section 4.1.4]. It also permits IdP-initiated SSO [SAML2Prof, section
4.1.5]. That is all well and good.

In metadata, however, the schema requires at least one
SingleSignOnService endpoint in every IDPSSODescriptor. That's
unfortunate since it forces every IdP (that relies on metadata) to
support SP-initiated SSO. An IdP that wishes to support IdP-initiated
SSO only is out of luck, at least in terms of metadata.

I would call that a bug (in the metadata schema). What do others think?

Tom
← Prev in month ← Prev in thread