OpenSAML: Verify Signature after decryption

Cantor, Scott cantor.2 at osu.edu
Thu Sep 8 17:17:53 BST 2011


On 9/8/11 11:50 AM, "Nicolas Peifer" <nicolaspeifer at gmx.de> wrote:
>
>I decrypted the Extension of an AuthnRequest successfully and now I'm
>trying 
>to verify the signature (of the whole request).

What kind of extension is encrypted? A signature over the AuthnRequest
would also not verify if you replace the encrypted content with the
plaintext. The signature has to be over the final form of the request.

-- Scott



More information about the dev mailing list