[JIRA] Updated: (IDP-76) Consider changing the default signAssertions setting for the SAML2AttributeQueryProfile
Chad La Joie (JIRA)
noreply at shibboleth.net
Fri Sep 9 14:19:26 BST 2011
[ https://issues.shibboleth.net/jira/browse/IDP-76?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Chad La Joie updated IDP-76:
----------------------------
Component/s: Security and Cryptography
SAML2
> Consider changing the default signAssertions setting for the SAML2AttributeQueryProfile
> ---------------------------------------------------------------------------------------
>
> Key: IDP-76
> URL: https://issues.shibboleth.net/jira/browse/IDP-76
> Project: Identity Provider
> Issue Type: Improvement
> Components: SAML2, Security and Cryptography
> Reporter: Kaspar Brand
> Assignee: Chad La Joie
> Priority: Minor
>
> This is sort of a followup on the thread "Moving the back channel on the IdP from port 8443 to 443: caveats, pitfalls?" I started on shib-users in January 2011 (https://lists.internet2.edu/sympa/arc/shibboleth-users/2011-01/msg00229.html).
> To switch to message-level security for attribute queries, too, the IdP's default of not signing assertions for the SAML2AttributeQueryProfile currently needs to be changed in the configuration.
> For version 3, I think it makes sense to consider changing the default for signAssertions to "always" , to support configurations relying on message-level security out of the box.
--
This message is automatically generated by JIRA.
For more information on JIRA, see: http://www.atlassian.com/software/jira
More information about the commits
mailing list