Passthrough of SAML response by SP to application
Cantor, Scott
cantor.2 at osu.edu
Mon Jul 16 10:16:37 EDT 2012
> [DW] I've just tried out Assertion Export, but I get a stripped-down SAML
> response, not the original (see attachment). In particular, all signature
> information is missing, which is necessary to re-validate the SAML response
> on the delegated web service (i.e. SP B wants to verify that "user X is
> authenticated and connected to SP A"). Is there any way to retrieve the
> cryptographic signature as well?
As I originally noted, you can't do that legally, the assertion is not valid for use by the downstream system.
In any case, it's not stripping anything. If it's not signed, it wasn't signed to begin with, probably the response was.
-- Scott
More information about the users
mailing list