As an SP, Force IdP to Encrypt Response
mpopatia
musab at stellic.com
Thu Mar 14 15:47:06 EDT 2019
As a service provider, is there any way to tell the IdP to encrypt their
response and maybe reject the response if it is not encrypted?
We are an SP and work with multiple IdPs and in the decoded SAML message, in
our DEBUG logs, we always get
<saml2:EncryptedAssertion>...</saml2:EncryptedAssertion> except for one IdP
which sends unencrypted data and the decoded SAML message contains
<saml2:Assertion>...</saml2:Assertion> directly. In this case, regardless of
the credentials in my <CredentialResolver>, I can see the attributes being
sent. Is there any way to tell the IdP that we expect them to encrypt the
data being sent?
Thanks.
--
Sent from: http://shibboleth.1660669.n2.nabble.com/Shibboleth-Developers-f1660781.html
More information about the dev
mailing list