Uploaded image for project: 'JBoss Enterprise Application Platform'
  1. JBoss Enterprise Application Platform
  2. JBEAP-5273

[GSS](7.0.z) PLINK-700 - SAML 2.0 Unsolicited Response MUST NOT contain an InResponseTo attribute

    XMLWordPrintable

Details

    • Bug
    • Resolution: Done
    • Major
    • 7.0.5.CR2, 7.0.5.GA
    • 7.0.1.CR2
    • Security
    • None
    • EAP 7.0.5

    Description

      When Using a SAML V2 Idp Initiated Single Sign On Scenario, the SAML Reponse that gets generated by PicketLink contains an InResponseTo attribute.

      SAML Spec says "An unsolicited <Response> MUST NOT contain an InResponseTo attribute, "

      Attachments

        Issue Links

          Activity

            People

              istudens@redhat.com Ivo Studensky
              vpakan Vlado Pakan (Inactive)
              Ivo Hradek Ivo Hradek (Inactive)
              Ivo Hradek Ivo Hradek (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              8 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: