Skip to main content

(7642 replaces this) Form control MUST be named SAMLRequest and SAMLResponse instead of samlToken

Portal Admin
Published on: 19/02/2010 Discussion Archived

We have discovered PEPS Demo application using samlToken in HTML form when exchanging base64 encoded SAMLAuthRequest and SAMLResponse. According to SAML V2.0 the form control must be named SAMLRequest and SAMLResponse. Bindings for the OASIS Security Assertion Markup Language (SAML) V2.0 If the message is a SAML request, then the form control MUST be named SAMLRequest. If the message is a SAML response, then the form control MUST be named SAMLResponse. Any additional form controls or presentation MAY be included but MUST NOT be required in order for the recipient to process the message.



HardwareNone
ProductS-PEPS
Operating SystemNone
ComponentInterfaces
Versionv1.1
Severitynormal
ResolutionNone
Reporter's emailNone

Category

Bugs
Login or create an account to comment.