unencrypted assertions not working

Mark K. Miller max at psu.edu
Wed Apr 3 10:21:06 EDT 2013


On Wed, 3 Apr 2013, lalithj wrote:

> Hi,
>
> We got a new SP requirment that they need unencrypted assertions, am not
> sure whether this is the best practice or not(which is a seperate question)

During new engagements I've had many SPs come back to me with this 
'requirement.'  I tell them, in my opinion, it is not a best practice, 
and refuse to do it.  I have them configure their SP to handle encrypted 
assertions.

I have no clue what federation/trust model the OP participates in, but, if 
I may jump on my 'InCommon soapbox' for a moment.  It's my opinion that 
its always best to guide new services in a direction that will require the 
least effort for them and their future business partners.  In this case, 
specifically, I think most of the IdPs in InCommon send encrypted 
assertions by default.  So, in the initial engagement, if we can get a new 
SP accepting encrypted assertions it's far less total effort for everyone 
in the long run.

Everyone's mileage varies,

Max


More information about the users mailing list