IdPXMLSigEnc Behavior unclear

Chad La Joie lajoie at itumi.biz
Fri Aug 19 12:41:24 BST 2011


Yeah, the assertion is actually generated by the profile handler that
sends the artifact and the conditional is based on the current request
not some future request.  So, the SSO profile handler is what is
making the determination, thats why its configuration option takes
effect, and it's the transport used by the SSO profile handler that is
used when computing the "conditional" aspect of that setting.

On Fri, Aug 19, 2011 at 07:30, Rainer Hoerbe <rainer at hoerbe.at> wrote:
> I expected that artifact resolution over TLS would not encrypt the assertion, but the  Shib IDP does with the default profile configuration in the default relying party:
> encryptAssertions="conditional" in SAML2SSOProfile, SAML2AttributeQueryProfile and SAML2ArtifactResolutionProfile.
>
> When I set encryptAssertions="never" for SAML2ArtifactResolutionProfile the assertions are still encrypted.
>
> When I set encryptAssertions="never" for SAML2SSOProfile the assertions are in clear.
>
> Is this the expected behavior? If yes, where could I find more documentation beyond the IdPXMLSigEnc page in the wiki? Sorry if that was answered already in the list, but I could not google it.
>
> Thanks for clarification
> Rainer Hörbe
> Stadt Wien, Austria
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>



-- 
Chad La Joie
www.itumi.biz
trusted identities, delivered


More information about the users mailing list