Subject: Re: [saml-dev] supporting the AuthnRequest protocol

On 3/17/13 3:15 PM, "Tom Scavo" <trscavo@gmail.com> wrote:
>In metadata, however, the schema requires at least one
>SingleSignOnService endpoint in every IDPSSODescriptor. That's
>unfortunate since it forces every IdP (that relies on metadata) to
>support SP-initiated SSO. An IdP that wishes to support IdP-initiated
>SSO only is out of luck, at least in terms of metadata.

Unless you just define a binding to represent what IdP-initiated SSO
really is, which is just a non-standard binding for a different sort of

>I would call that a bug (in the metadata schema). What do others think?

I think it's irrelevant, since it can't be fixed, but is fortunately an
easily worked around problem.

-- Scott

