Simulating Invalid Request From RP
Zmuda, Matthew R
Matthew.R.Zmuda at td.com
Thu Dec 1 12:40:18 GMT 2011
I have both an RP and IDP running locally. I'd like to test the scenario where the request from RP is not signed appropriately (or has been tampered with on the way over).
What specifically in the IDP would cause it to reject a RP request that say has not been signed as expected? I have tried modifying the certificates in rp and idp metadata on RP side and have not been able to cause the IDP to reject a AuthNRequest.
My IDP does have the following defined in the SecurityPolicy:
<security:Rule xsi:type="samlsec:SAML2AuthnRequestsSigned"/>
<security:Rule xsi:type="samlsec:ProtocolWithXMLSignature" trustEngineRef="shibboleth.SignatureTrustEngine"/>
<security:Rule xsi:type="samlsec:SAML2HTTPRedirectSimpleSign" trustEngineRef="shibboleth.SignatureTrustEngine"/>
<security:Rule xsi:type="samlsec:SAML2HTTPPostSimpleSign" trustEngineRef="shibboleth.SignatureTrustEngine"/>
Thanks
NOTICE: Confidential message which may be privileged. Unauthorized use/disclosure prohibited. If received in error, please go to www.td.com/legal for instructions.
AVIS : Message confidentiel dont le contenu peut être privilégié. Utilisation/divulgation interdites sans permission. Si reçu par erreur, prière d'aller au www.td.com/francais/avis_juridique pour des instructions.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20111201/273506fe/attachment.html
More information about the users
mailing list