Simulating Invalid Request From RP

Chad La Joie lajoie at itumi.biz
Thu Dec 1 13:23:45 GMT 2011


Yes, those rules are the ones that deal with incoming requests and
whether they are signed or not.

On Thu, Dec 1, 2011 at 07:40, Zmuda, Matthew R <Matthew.R.Zmuda at td.com> wrote:
> I have both an RP and IDP running locally. I’d like to test the scenario
> where the request from RP is not signed appropriately (or has been tampered
> with on the way over).
>
> What specifically in the IDP would cause it to reject a RP request that say
> has not been signed as expected? I have tried modifying the certificates in
> rp and idp metadata on RP side and have not been able to cause the IDP to
> reject a AuthNRequest.
>
>
>
> My IDP does have the following defined in the SecurityPolicy:
>
>
>
>         <security:Rule xsi:type="samlsec:SAML2AuthnRequestsSigned"/>
>
>         <security:Rule xsi:type="samlsec:ProtocolWithXMLSignature"
> trustEngineRef="shibboleth.SignatureTrustEngine"/>
>
>         <security:Rule xsi:type="samlsec:SAML2HTTPRedirectSimpleSign"
> trustEngineRef="shibboleth.SignatureTrustEngine"/>
>
>         <security:Rule xsi:type="samlsec:SAML2HTTPPostSimpleSign"
> trustEngineRef="shibboleth.SignatureTrustEngine"/>
>
>
>
> Thanks
>
> NOTICE: Confidential message which may be privileged. Unauthorized
> use/disclosure prohibited. If received in error, please go to
> www.td.com/legal for instructions.
> AVIS : Message confidentiel dont le contenu peut être privilégié.
> Utilisation/divulgation interdites sans permission. Si reçu par erreur,
> prière d'aller au www.td.com/francais/avis_juridique pour des instructions.
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>



-- 
Chad La Joie
www.itumi.biz
trusted identities, delivered


More information about the users mailing list