IdPXMLSigEnc Behavior unclear
Rainer Hoerbe
rainer at hoerbe.at
Fri Aug 19 14:36:41 BST 2011
Am 19.08.2011 um 14:59 schrieb Chad La Joie:
> No, but that's not the channel determining whether the assertion is
> encrypted. As I said, *everything* about the generation of the
> assertion occurs within the scope of the SSO profile handler. The
> artifact resolver does not, in any way, touch the assertion, it just
> looks it up from an internal map and sticks it in the response.
>
> I think what you're getting at is that the XML encryption is
> potentially wasted effort when the assertion is actually being fetched
> by means of an artifact, and thats true. There is an RFE for the IdP
> to address this already. But for right now, everything is working as
> designed.
Tx, that was what I missed to understand.
More information about the users
mailing list