Failure to validate Response Signature
Rainer Hoerbe
rainer at hoerbe.at
Fri Oct 5 18:09:13 EDT 2012
>>
>>> Adding a <PolicyRule type="Ignore">saml2:OneTimeUse</PolicyRule> under
>>> Conditions did not change anything. I even checked that the IDP issued
>>> unique IDs for each response and assertion. Is there some documentation
>>> to read more about the OneTimeUse?
>>
>> It's not a part of the SSO profile. Using the Ignore syntax should work.
>
> I assume the sample you posted in the bug includes that condition also, so
> I can verify that issue at the same time to see if there's a bug around
> it. Oddly though, when I created the Ignore rule, I tested it specifically
> with that condition type, so I imagine it's a syntax thing.
If you need I can check out that version of security-policy.xml from my svn.
- Rainer
More information about the users
mailing list