IdPXMLSigEnc Behavior unclear

Rainer Hoerbe rainer at hoerbe.at
Fri Aug 19 14:36:41 BST 2011


Am 19.08.2011 um 14:59 schrieb Chad La Joie:

> No, but that's not the channel determining whether the assertion is
> encrypted.  As I said, *everything* about the generation of the
> assertion occurs within the scope of the SSO profile handler.  The
> artifact resolver does not, in any way, touch the assertion, it just
> looks it up from an internal map and sticks it in the response.
> 
> I think what you're getting at is that the XML encryption is
> potentially wasted effort when the assertion is actually being fetched
> by means of an artifact, and thats true.  There is an RFE for the IdP
> to address this already.  But for right now, everything is working as
> designed.

Tx, that was what I missed to understand. 



More information about the users mailing list