Previous Topic: How the Consumer Obtains the Assertion

Next Topic: Configure the SAML Session Ticket Authentication Scheme

How the Consumer Uses the Assertion

In the chain authentication service model, the web service consumer obtains a SAML Session Ticket assertion from the first web service in the chain upon successful authentication. That assertion is subsequently used by other web services in the chain to authenticate the request.

After the assertion and document are issued by the first web service, it passes the document to the next web service in the chain. When a downstream web service receives the document, the SAML Session Ticket authentication scheme verifies the document’s signature and validates the originator of the document based on the session ticket in the assertion. The application receiving this document may now process it and send it along to other web services protected by the SAML authentication scheme.