Failure to validate Response Signature

Rainer Hoerbe rainer at hoerbe.at
Fri Oct 5 18:09:13 EDT 2012


>> 
>>> Adding a <PolicyRule type="Ignore">saml2:OneTimeUse</PolicyRule> under
>>> Conditions did not change anything. I even checked that the IDP issued
>>> unique IDs for each response and assertion. Is there some documentation
>>> to read more about the OneTimeUse?
>> 
>> It's not a part of the SSO profile. Using the Ignore syntax should work.
> 
> I assume the sample you posted in the bug includes that condition also, so
> I can verify that issue at the same time to see if there's a bug around
> it. Oddly though, when I created the Ignore rule, I tested it specifically
> with that condition type, so I imagine it's a syntax thing.


If you need I can check out that version of security-policy.xml from my svn.

- Rainer


More information about the users mailing list