IdPXMLSigEnc Behavior unclear
Rainer Hoerbe
rainer at hoerbe.at
Fri Aug 19 13:50:00 BST 2011
Is it the correct and expected default behavior with encryptAssertions="conditional" that the assertion is encrypted over the TLS-secured SOAP channel?
Am 19.08.2011 um 13:41 schrieb Chad La Joie:
> Yeah, the assertion is actually generated by the profile handler that
> sends the artifact and the conditional is based on the current request
> not some future request. So, the SSO profile handler is what is
> making the determination, thats why its configuration option takes
> effect, and it's the transport used by the SSO profile handler that is
> used when computing the "conditional" aspect of that setting.
>
> On Fri, Aug 19, 2011 at 07:30, Rainer Hoerbe <rainer at hoerbe.at> wrote:
>> I expected that artifact resolution over TLS would not encrypt the assertion, but the Shib IDP does with the default profile configuration in the default relying party:
>> encryptAssertions="conditional" in SAML2SSOProfile, SAML2AttributeQueryProfile and SAML2ArtifactResolutionProfile.
More information about the users
mailing list