ProfileConfiguration - signResponses="always" signAssertions="always"
Chad La Joie
lajoie at shibboleth.net
Wed Feb 29 14:31:45 GMT 2012
Completely depends on your use case.
Normally you only need to sign one of them. Because the response
doesn't carry any sensitive information and because there are use cases
where you want to be able to snip out the Assertion and use it and
maintain the signature we moved our default configs to not sign the
response but instead sign the assertion.
Whether that makes sense for your deployment or not is really something
you have to decide.
On 2/29/12 9:15 AM, Zmuda, Matthew R wrote:
> Does it make sense to ever sign both response and assertion?
>
> To me it seems like signing both may be unnecessary processing.
More information about the users
mailing list