<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html;
      charset=windows-1252">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    <p><br>
    </p>
    <br>
    <div class="moz-cite-prefix">On 4/27/17 12:35 AM, Locatelli da
      Silva, Thiago wrote:<br>
    </div>
    <blockquote type="cite"
      cite="mid:D526E57D.D81D%25thiago.locatellidasilva@transamerica.com">
      <meta http-equiv="Content-Type" content="text/html;
        charset=windows-1252">
      <div>
        <div style="font-family: Calibri, sans-serif; font-size: 14px;
          color: rgb(0, 0, 0);">
          <br>
        </div>
        <div style="font-family: Calibri, sans-serif; font-size: 14px;
          color: rgb(0, 0, 0);">
          These are the steps I am following to create my Response with
          Encrypted Assertion</div>
        <ol>
          <li style="font-family: Calibri, sans-serif; font-size: 14px;
            color: rgb(0, 0, 0);">
            Create Assertion (able to marshall)</li>
          <li style="font-family: Calibri, sans-serif; font-size: 14px;
            color: rgb(0, 0, 0);">
            Sign Assertion (able to marshall)</li>
          <li style="font-family: Calibri, sans-serif; font-size: 14px;
            color: rgb(0, 0, 0);">
            Validate Assertion signature</li>
          <li><font color="#ff0000"><font face="Calibri,sans-serif">Encrypt
                Assertion (marshaling fails)</font></font></li>
        </ol>
        <div style="font-family: Calibri, sans-serif; font-size: 14px;
          color: rgb(0, 0, 0);">
          <br>
        </div>
      </div>
    </blockquote>
    <br>
    If per #3 you really are validating the Signature in the same
    program after you sign: I know that historically in some versions of
    Santuario (XML security lib) that was a problem.  But not sure about
    now.  But you also don't really need to do that, I would think,
    outside of some initial testing.  Once you sign, you can be assured
    it's valid.  It's also somewhat expensive to do that, if you are
    concerned about computational cost.<br>
    <br>
    <br>
    <br>
    <blockquote type="cite"
      cite="mid:D526E57D.D81D%25thiago.locatellidasilva@transamerica.com">
      <div>
        <div style="font-family: Calibri, sans-serif; font-size: 14px;
          color: rgb(0, 0, 0);">
        </div>
        <div style="font-family: Calibri, sans-serif; font-size: 14px;
          color: rgb(0, 0, 0);">
          There might be missing something with my method that receives
          and Assertion and returns a EncryptedAssertion. </div>
      </div>
    </blockquote>
    <br>
    It looks fine to me.  There's not much to encryption, that's a
    pretty simple case.  (OTOH, *decryption* has some issues to be aware
    of there, wrt the DOM of the decrypted content, as described in the
    Javadocs).<br>
    <br>
    <blockquote type="cite"
      cite="mid:D526E57D.D81D%25thiago.locatellidasilva@transamerica.com">
      <div>
        <div style="font-family: Calibri, sans-serif; font-size: 14px;
          color: rgb(0, 0, 0);">I am currently using JDK 1.8 from Oracle
          on MacOS and I guess I am using jaxp that is internal to the
          JRE because the only dependencies on my POM are OpenSAML
          dependencies.</div>
        <br>
      </div>
    </blockquote>
    <br>
    That should be fine.  I mainly just wanted to confirm that you
    weren't endorsing some possibly-buggy version of Xerces, etc.<br>
  </body>
</html>