<div dir="ltr">Hi,<div><br></div><div>I never internalized before that the default configuration for SAML2 browser SSO is to NOT sign assertions and so "out of the box" the IdP v3 is not SAML2int compliant.</div><div><br></div><div>I imagine there is a historical reason for that?</div><div><br></div><div>Just curious,</div><div><br></div><div>Scott K</div></div>