OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

saml-dev message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: [saml-dev] how to verify the sender of a SAML authn request


On 8/1/13 5:44 PM, "Mitu Singh" <mitusingh27@yahoo.com> wrote:
>
>I have a question regarding the SAML Authentication Request. When an IDP
>receives a SAML authentiocation request, how can they validate the sender
>of the request? The issuer name, provider name,
>AssertionConsumerServiceURL and the signature are all optional.

They aren't optional in the context of specific profiles.

-- Scott




[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]