IdPXMLSigEnc Behavior unclear

Rainer Hoerbe rainer at hoerbe.at
Fri Aug 19 12:30:02 BST 2011


I expected that artifact resolution over TLS would not encrypt the assertion, but the  Shib IDP does with the default profile configuration in the default relying party:
encryptAssertions="conditional" in SAML2SSOProfile, SAML2AttributeQueryProfile and SAML2ArtifactResolutionProfile.

When I set encryptAssertions="never" for SAML2ArtifactResolutionProfile the assertions are still encrypted.

When I set encryptAssertions="never" for SAML2SSOProfile the assertions are in clear.

Is this the expected behavior? If yes, where could I find more documentation beyond the IdPXMLSigEnc page in the wiki? Sorry if that was answered already in the list, but I could not google it.

Thanks for clarification
Rainer Hörbe
Stadt Wien, Austria



More information about the users mailing list