Defaults for encryption and signing predicates in SAML profiles
Rod Widdowson
rdw at steadingsoftware.com
Tue Apr 29 05:01:40 EDT 2014
While I was adding the parse for encryptAttributes to the SAML2 profiles I
realized that in porting the parsers over from V2 I was bring with them the
"defaulted in the setter" paradigm for the signing and encryption
predicates. We are hoping to avoid this non-obvious behaviour and so by way
of an experiment I turned this off.
Several defaulting tests failed indicating that the V3 defaults are not V2
defaults. Some of this is to do with the funky "conditional" type that the
V2 config allows.
I'm vaguely disquieted by this, but not enough (yet) to do a full analysis
of where the differences are. If however others share my disquiet I'll do
an analysis of the two systems and circulate a table of where they differ.
Rod
More information about the dev
mailing list