SAML 2.0 - Multiple AssertionConsumerService in SP

后端 未结 2 1890
眼角桃花
眼角桃花 2021-01-15 14:20



I implement a SAML 2.0 SP.
I have a login servlet with endpoint https://my.domain.com/mng/samlLogin, so in the SP metadata file I define:

&l         


        
2条回答
  •  北恋
    北恋 (楼主)
    2021-01-15 15:05

    Yes, you can include additional elements in the SAML 2.0 SP metadata with the same binding, each with its own unique index. Alternatively you can choose to sign the authentication requests as the SP in which case you can freely specify an AssertionConsumerServiceURL without the requirement that it was published and configured earlier as part of the SP metadata exchange.

    This is all spec compliant but be aware (as always with "advanced" SAML options) that your mileage may vary wrt. support across different SAML implementations.

提交回复
热议问题