Implications of forceAuthn/AuthnInstant
Eric Goodman
Eric.Goodman at ucop.edu
Thu Oct 10 18:41:13 EDT 2013
Thanks again.
>4) SP operator ensures that any relied upon IdPs require signed
>AuthnRequests from this SP
I made an assumption here that requiring signed AuthnRequests can be done on an SP-by-SP basis. Is SP-by-SP control possible?
It appears that requiring AuthnRequest signing would be done in relying-party.xml in the SecurityPolicy section for the relevant protocol (e.g., shibboleth.SAML2SSOSecurityPolicy) by adding the appropriate rule (security:MandatoryMessageAuthentication?) But those rules look fairly global to the RelyingPartyGroup element, and not clearly scopeable to individual RPs or ProfileConfigurations.
--- Eric
More information about the users
mailing list