As an SP, Force IdP to Encrypt Response

mpopatia musab at stellic.com
Thu Mar 14 15:47:06 EDT 2019


As a service provider, is there any way to tell the IdP to encrypt their
response and maybe reject the response if it is not encrypted?

We are an SP and work with multiple IdPs and in the decoded SAML message, in
our DEBUG logs, we always get
<saml2:EncryptedAssertion>...</saml2:EncryptedAssertion> except for one IdP
which sends unencrypted data and the decoded SAML message contains
<saml2:Assertion>...</saml2:Assertion> directly. In this case, regardless of
the credentials in my <CredentialResolver>, I can see the attributes being
sent. Is there any way to tell the IdP that we expect them to encrypt the
data being sent?

Thanks.



--
Sent from: http://shibboleth.1660669.n2.nabble.com/Shibboleth-Developers-f1660781.html


More information about the dev mailing list