Odd behavior when signing SAML 1.1 Assertion w/ Advice
Cantor, Scott
cantor.2 at osu.edu
Thu Oct 9 10:25:17 EDT 2014
On 10/9/14, 8:00 AM, "Stephen.CTR.Chappell at faa.gov"
<Stephen.CTR.Chappell at faa.gov> wrote:
>
>The code I¹m using to sign the assertion is based heavily on the WSS4J
>AssertionWrapper signAssertion code. Here it is:
I don't see anything there that actually signs the assertion, but that
aside, and notwithstanding that I don't really know the Java well enough
to comment, it looks questionable to me that you're dropping the DOM at
the end, because I don't recall the Java code ever having full round trip
fidelity when the DOM isn't cached, particularly when signatures are
involved.
-- Scott
More information about the dev
mailing list