Uploaded image for project: 'JBoss Enterprise Application Platform'
  1. JBoss Enterprise Application Platform
  2. JBEAP-5273

[GSS](7.0.z) PLINK-700 - SAML 2.0 Unsolicited Response MUST NOT contain an InResponseTo attribute

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Major Major
    • 7.0.5.CR2, 7.0.5.GA
    • 7.0.1.CR2
    • Security
    • None
    • EAP 7.0.5

      When Using a SAML V2 Idp Initiated Single Sign On Scenario, the SAML Reponse that gets generated by PicketLink contains an InResponseTo attribute.

      SAML Spec says "An unsolicited <Response> MUST NOT contain an InResponseTo attribute, "

            istudens@redhat.com Ivo Studensky
            vpakan Vlado Pakan (Inactive)
            Ivo Hradek Ivo Hradek (Inactive)
            Ivo Hradek Ivo Hradek (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            8 Start watching this issue

              Created:
              Updated:
              Resolved: