Hacker News new | ask | show | jobs
by 35fbe7d3d5b9 1918 days ago
This is a direct result of a spec that basically says "here's a grab bag of options, pick what suits you".

Maybe your IdP expects SOAP over HTTP but your SP won't. Perhaps the SP insists on encrypting AuthnRequests. God help you if one side wants to do URL encoding and DEFLATE.

I've made my life easier by refusing to ask/answer questions around SSO and instead insisting on talking about "ADFS login". We still do SAML, but at least there's a baseline implementation that I can plan for.