13.07.2015 Views

Liberty ID-FF Bindings and Profiles Specification - Liberty Alliance

Liberty ID-FF Bindings and Profiles Specification - Liberty Alliance

Liberty ID-FF Bindings and Profiles Specification - Liberty Alliance

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>Liberty</strong> <strong>Alliance</strong> Project:<strong>Liberty</strong> <strong>ID</strong>-<strong>FF</strong> <strong>Bindings</strong> <strong>and</strong> <strong>Profiles</strong> <strong>Specification</strong>Version: 1.2-errata-v2.0838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872• WML Redirect with GET...Contacting IdP. Please wait.........where:This element provides the host name, port number, <strong>and</strong> path components of the single sign-on service URL at theidentity provider.= ... ...A component MUST contain a single authentication request:A component MUST contain a single authentication request message inbase64-encoded form.3.2.2.1.2. Step 6: Redirecting to the Service ProviderIn step 6, the identity provider instructs the user agent to access the service provider’s assertion consumer serviceURL, <strong>and</strong> provides a SAML artifact for de-referencing by the service provider.This step may take place via an HTTP 302 redirect, a WML redirect deck or any other method that results in the useragent being instructed to make an HTTP GET or POST request to the service provider’s assertion consumer service.This response MUST adhere to the following rules:873874875876877878879880• The response MUST contain the service provider’s assertion consumer service URL (for example, as the Locationheader of an HTTP 302 redirect, the action attribute of an HTMLform or the href attribute of a elementin a WML redirect deck).• The service provider’s assertion consumer service URL MUST specify https as the URL scheme.Note:Future protocols may be adopted <strong>and</strong> enabled to work within this framework. Therefore, implementers areencouraged to not hardcode a reliance on https.• The response MUST include one of the following:<strong>Liberty</strong> <strong>Alliance</strong> Project24

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!