When configuring the IdP, which parameter does the ISVA use in the SAML configuration, to fill the <saml:Audience> ??? </saml:Audience> in the <samlp:Response>
In other words, If I need to change this parameter, where can I do it?
I am also trying to replicate the browser behavior using "curl", but I am having a different response when invoking the SP /junction/sps/federation/saml20/login endpoint.
In the browser I am getting an 302 while using the curl, I am getting a 200 OK?
------------------------------
Joao Goncalves
Pyxis, Lda.
Sintra
+351 91 721 4994
------------------------------
Original Message:
Sent: Mon April 05, 2021 03:35 AM
From: Peter Gierveld
Subject: SAML inconsistent documentation?
Hi Joao,
To be more specific, the login endpoint is one of the SAML2 protocol Location urls mentioned in SAML2 metadata, for either the IdP (SingleSignOnService) or SP (AssertionConsumerService) depending on the role your federation has.
The logininitial is a TFIM/ISAM/ISVA specific endpoint to start an SAML2 IdP initiated login (I know other products use different urls and querystring parameters to start the IdP initiated flows; Note that the use of Target in this context is IBM specific). The wssoi endpoint is meant to keep track of things as a user might or might not already have a valid session with the Point-of-Contact.
Peter
------------------------------
Peter Gierveld
Security Architect
SecurIT
Amsterdam
------------------------------
Original Message:
Sent: Sat April 03, 2021 10:49 AM
From: Jon Harry
Subject: SAML inconsistent documentation?
Hi Joao,
the logininitial endpoint is the trigger endpoint. It's what you call to initiate an SSO flow.
the login endpoint is the endpoint that receives SAML messages. It is the true endpoint that you would configure at a partner system.
Jon.
------------------------------
Jon Harry
Consulting IT Security Specialist
IBM