unsigned authN requests
David Bantz
dabantz at alaska.edu
Wed Jun 5 21:10:08 EDT 2013
The metadata I do have contains this:
<md:SPSSODesriptor ID=… … AuthRequestSigned="true"…
David Bantz
On Wed, 5 Jun 2013, at 16:50 , "Cantor, Scott" <cantor.2 at osu.edu> wrote:
> On 6/5/13 8:31 PM, "Brent Putman" <putmanb at georgetown.edu> wrote:
>>
>> It sounds like this isn't the problem, but just wanted to comment that:
>> Actually, you can get an unsigned SAML 2 AuthnRequest that fails the
>> IdP's security policy (just b/c it's unsigned) if the SP's metadata says
>> that it will sign requests. That's what this security rule does:
>>
>> <security:Rule xsi:type="samlsec:SAML2AuthnRequestsSigned"/>
>>
>> I doubt anyone uses that much, but that's what it does, enforce the
>> SPSSODescriptor/@AuthnRequestsSigned metadata attribute semantics.
>
> Ah, right. I don't think that fits the log, but worth checking.
>
> -- Scott
>
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list