OpenSAML Encryption

Cantor, Scott cantor.2 at osu.edu
Sat Nov 24 19:56:42 EST 2018


On 11/22/18, 7:36 AM, "dev on behalf of Martin Doležal" <dev-bounces at shibboleth.net on behalf of martin.dolezal at noctuint.cz> wrote:

> Yeah, sounds like me, doing very impressive things our customer asks
> for ;-) (if true)

It's borderline unbelievable given the total lack of documentation and the complexity of the subject matter. I guess the API doxygen docs are something at least.

> And because from my SP side of view I have to send (at least for now)
> only AuthnRequest and LogoutRequest then I guess I really need (or may)
> to encrypt only NameId in LogoutRequest.

If you need logout, then yes, but you should avoid non-transient NameIDs and then you don't need encryption there.

-- Scott




More information about the dev mailing list