SP-specific failure to generate 'good' SAML assertion

David Bantz dabantz at alaska.edu
Tue Nov 12 20:58:44 EST 2013


Thanks Scott.
db

On Tue, 12 Nov 2013, at 16:28 , Cantor, Scott <cantor.2 at osu.edu> wrote:

>> 
>> Not the same SAML, no.
> 
> Your new output has the transient ID encrypted inside the EncryptedID
> element. You normally don't want to encrypt just the NameID, and a lot of
> SPs can't handle that either.
> 
> I don't know what the SP needs, but you should generally set the
> encryptNameID option or whatever it's called to never, and conditionally
> encrypt the assertion. (Or not encrypt at all for that SP if it doesn't
> handle that.)
> 
> Anway, bottom line, you fixed the transient ID release problem.
> 
> -- Scott
> 
> 
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 163 bytes
Desc: Message signed with OpenPGP using GPGMail
Url : http://shibboleth.net/pipermail/users/attachments/20131112/6a73e384/attachment.bin 


More information about the users mailing list