Decryption config

Cantor, Scott cantor.2 at osu.edu
Wed May 28 23:32:59 EDT 2014


On 5/28/14, 10:06 PM, "Cantor, Scott" <cantor.2 at osu.edu> wrote:

>The SAML 2 tests are now encrypting a NameID of jdoe inside the
>AuthnRequest, and the IdP is successfully decrypting that. It worked with
>and without a KeyInfo.

This also works now for legacy relying-party.xml usage, but I did that by
overloading the signingCredentialRef to be the decryption key, which may
not be what we want. We'd have to extend the schema to avoid that, of
course, or just not support it.

-- Scott




More information about the dev mailing list