How to Ignore a Signature
Henry B. Hotz
hotz at jpl.nasa.gov
Mon Aug 6 13:20:15 EDT 2012
Thanks!
On Aug 4, 2012, at 3:07 PM, Brent Putman wrote:
>
> On 8/4/12 5:12 PM, Henry B. Hotz wrote:
>>
>> I don't suppose there is any way to disable that rule for only one SP?
>>
>
> Yes, although I don't think we have it documented well on the wiki. Create a custom RelyingParty definition for that SP, documented here:
>
> https://wiki.shibboleth.net/confluence/display/SHIB2/IdPRelyingParty
>
> Probably want to start by just copying the ProfileConfigurations verbatim from the DefaultRelyingParty.
>
> Copy the <SecurityPolicy> for SAML 2 SSO, changing what you want, and giving it a new id.
>
> Then add a securityPolicyRef attribute on the profile config to link the new SecurityPolicy to the custom RP's profile configuration:
>
> <ProfileConfiguration xsi:type="saml:SAML2SSOProfile" securityPolicyRef="your-new-policy-id" ...other attributes... />
------------------------------------------------------
The opinions expressed in this message are mine,
not those of Caltech, JPL, NASA, or the US Government.
Henry.B.Hotz at jpl.nasa.gov, or hbhotz at oxy.edu
More information about the users
mailing list