How to verify the message signature with HTTPRedirectDeflateDecoder?

Yang, Gang CTR (US) gang.yang.ctr at mail.mil
Thu Apr 7 10:36:32 EDT 2016


Hi,



I'm using OpenSAML 2.5.1 to implement SSO using SAML 2.0 Redirect Binding/Profile. I've got the sending and receiving working. But I noticed that the receiving side did not seem to verify the signature. Of course I may not have set it up to do so, but I don't know how. I have the following questions and hope someone knowledgeable would provide some help and poitners.



- Based on my understanding, SAML 2.0 Redirect Binding does not send the signing certificate. Is this correct? I need it for encrypting the returned SAML assertion.



- If the above it true, how does the receiving side obtain the right cert and verify the signature? Metadata? What if I did not implement Metadata?



- How is HTTPRedirectDeflateDecoder designed to work in regard to signature verification? Is it out side the scope of HTTPRedirectDeflateDecoder, or there is some setup to be done in order to get the signature verified?



Thank you very much in advance.



Gang Yang

Shonborn-Becker Systems Inc. (SBSI)
Contractor Engineering Supporting SEC
Office: 732-982-8561, x427

Cell: 732-788-7501<tel:732-740-4656>
Email: gang.yang.ctr at mail.mil<mailto:gang.yang.ctr at mail.mil>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/dev/attachments/20160407/4b0cf385/attachment.html>


More information about the dev mailing list