13.07.2015 Views

Liberty ID-FF Bindings and Profiles Specification - Liberty Alliance

Liberty ID-FF Bindings and Profiles Specification - Liberty Alliance

Liberty ID-FF Bindings and Profiles Specification - Liberty Alliance

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>Liberty</strong> <strong>Alliance</strong> Project:<strong>Liberty</strong> <strong>ID</strong>-<strong>FF</strong> <strong>Bindings</strong> <strong>and</strong> <strong>Profiles</strong> <strong>Specification</strong>Version: 1.2-errata-v2.015441545154615471548154915501551155215531554155515561557155815591560= . . .RelayState=The component MUST contain the identical RelayState parameter <strong>and</strong> its value that was received in theURL-encoded federation termination message obtained in step 3. If no RelayState parameter was provided in the step3 message, then a RelayState parameter MUST NOT be specified in the component.3.4.1.1.6. Step 6: Accessing the Identity Provider Return URLIn step 6, the user agent accesses the identity provider’s return URL location fulfilling the redirect request.3.4.1.1.7. Step 7: ConfirmationIn step 7, the user agent is sent an HTTP response that confirms the requested action of identity federation terminationwith the specific service provider.3.4.1.2. SOAP/HTTP-Based ProfileThe SOAP/HTTP-based profile relies on using asynchronous SOAP over HTTP to communicate federation terminationnotification messages from the identity provider to the service provider. See Figure 11.The following URI-based identifier MUST be used when referencing this specific profile:URI: http://projectliberty.org/profiles/fedterm-idp-soapThis URI identifier MUST be specified in the service provider metadata element FederationTerminationNotification-ProtocolProfile when the service provider intends to indicate to the identity provider a preference for receiving federationtermination notifications via SOAP over HTTP.User AgentService ProviderIdentity Provider1. GET ()2. SOAP POST: ()3. ProcessRequest4: 204 OK:()1561156215635: 200 OK: ()Figure 11. SOAP/HTTP-based profile for federation terminationThis profile description assumes the following preconditions:156415651566• The Principal’s identity at the service provider is federated with his/her identity at the identity provider.• The Principal has authenticated with the identity provider.• The Principal has requested that the identity provider terminate the federation.<strong>Liberty</strong> <strong>Alliance</strong> Project44

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!