question about IdP initiated SSO
Paul Hethmon
paul.hethmon at clareitysecurity.com
Fri Jul 26 13:49:46 EDT 2013
Only if they are willing to share their private key with you so you can sign the message.
Paul
From: Joy Veronneau <jv11 at cornell.edu<mailto:jv11 at cornell.edu>>
Reply-To: Shibboleth Users <users at shibboleth.net<mailto:users at shibboleth.net>>
Date: Friday, July 26, 2013 1:09 PM
To: Shibboleth Users <users at shibboleth.net<mailto:users at shibboleth.net>>
Subject: question about IdP initiated SSO
Hi,
I am working on configuring our IdP (v 2.3.3) with Skillsoft. We want to use IdP initiated SSO, and we also use IdP initiated SSO for some other vendors (WebEx and WorkDay among them.)
My question centers around using
AuthnRequestsSigned="true"
in the Skillsoft SP metadata. If I set this to false, then everything works. If I set it to true, as they would like it set, then I get this error on the IdP:
11:37:28.033 - ERROR [org.opensaml.saml2.binding.security.SAML2AuthnRequestsSignedRule:87] - SPSSODescriptor for entity ID 'https://sso.skillport.com' indicates AuthnRequests must be signed, but inbound message was not signed
11:37:28.038 - WARN [edu.internet2.middleware.shibboleth.idp.profile.saml2.SSOProfileHandler:348] - Message did not meet security requirements
org.opensaml.ws.security.SecurityPolicyException: Inbound AuthnRequest was required to be signed but was not
Is there a way to configure IdP initiated SSO for AuthnRequestsSigned="true" without breaking our other IdP initiated SSO implementations?
Thanks,
Joy
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130726/b3d1ee18/attachment.html
More information about the users
mailing list