<html dir="ltr">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style id="owaParaStyle">P {
        MARGIN-BOTTOM: 0px; MARGIN-TOP: 0px
}
</style>
</head>
<body ocsi="0" fpstyle="1">
<div style="color: rgb(0, 0, 0); font-family: Tahoma; font-size: 10pt; direction: ltr;">
<div>
<p>Hi,</p>
<p> </p>
<p>I'm using OpenSAML 2.5.1 to implement SSO using SAML 2.0 Redirect Binding/Profile. I've got the sending and receiving working. But I noticed that the receiving side did not seem to verify the signature. Of course I may not have set it up to do so, but I
 don't know how. I have the following questions and hope someone knowledgeable would provide some help and poitners.</p>
<p> </p>
<p>- Based on my understanding, SAML 2.0 Redirect Binding does not send the signing certificate. Is this correct? I need it for encrypting the returned SAML assertion.</p>
<p> </p>
<p>- If the above it true, how does the receiving side obtain the right cert and verify the signature? Metadata? What if I did not implement Metadata?</p>
<p> </p>
<p>- How is HTTPRedirectDeflateDecoder designed to work in regard to signature verification? Is it out side the scope of HTTPRedirectDeflateDecoder, or there is some setup to be done in order to get the signature verified?</p>
<p> </p>
<p>Thank you very much in advance.</p>
<p> </p>
<div style="font-family: Tahoma; font-size: 13px;">
<p>Gang Yang</p>
<p>Shonborn-Becker Systems Inc. (SBSI)<br>
Contractor Engineering Supporting SEC<br>
Office: 732-982-8561, x427</p>
<p>Cell: <a href="tel:732-740-4656" target="_blank" value="+17327404656"><font color="#222222">732-788-7501</font></a><br>
Email: <a href="mailto:gang.yang.ctr@mail.mil" target="_blank"><font color="#222222">gang.yang.ctr@mail.mil</font></a></p>
</div>
</div>
</div>
</body>
</html>