question about IdP initiated SSO

Paul Hethmon paul.hethmon at clareitysecurity.com
Fri Jul 26 13:49:46 EDT 2013


Only if they are willing to share their private key with you so you can sign the message.

Paul

From: Joy Veronneau <jv11 at cornell.edu<mailto:jv11 at cornell.edu>>
Reply-To: Shibboleth Users <users at shibboleth.net<mailto:users at shibboleth.net>>
Date: Friday, July 26, 2013 1:09 PM
To: Shibboleth Users <users at shibboleth.net<mailto:users at shibboleth.net>>
Subject: question about IdP initiated SSO

Hi,

I am working on configuring our IdP (v 2.3.3) with Skillsoft. We want to use IdP initiated SSO, and we also use IdP initiated SSO for some other vendors (WebEx and WorkDay among them.)

My question centers around using
AuthnRequestsSigned="true"

in the Skillsoft SP metadata. If I set this to false, then everything works. If I set it to true, as they would like it set, then I get this error on the IdP:

11:37:28.033 - ERROR [org.opensaml.saml2.binding.security.SAML2AuthnRequestsSignedRule:87] - SPSSODescriptor for entity ID 'https://sso.skillport.com' indicates AuthnRequests must be signed, but inbound message was not signed
11:37:28.038 - WARN [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:348] - Message did not meet security requirements
org.opensaml.ws.security.SecurityPolicyException: Inbound AuthnRequest was required to be signed but was not

Is there a way to configure IdP initiated SSO for AuthnRequestsSigned="true" without breaking our other IdP initiated SSO implementations?

Thanks,

Joy



-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130726/b3d1ee18/attachment.html 


More information about the users mailing list