Re: [saml-dev] how to verify the sender of a SAML authn request

From
Cantor, Scott <>
Date
2013-08-01T22:12:54+00:00
ID
Thread
Re: [saml-dev] how to verify the sender of a SAML authn request
On 8/1/13 5:44 PM, "Mitu Singh" <> wrote:
>
>I have a question regarding the SAML Authentication Request. When an IDP
>receives a SAML authentiocation request, how can they validate the sender
>of the request? The issuer name, provider name,
>AssertionConsumerServiceURL and the signature are all optional.

They aren't optional in the context of specific profiles.

-- Scott