Implications of forceAuthn/AuthnInstant

Eric Goodman Eric.Goodman at ucop.edu
Thu Oct 10 18:41:13 EDT 2013


Thanks again.

>4) SP operator ensures that any relied upon IdPs require signed 
>AuthnRequests from this SP

I made an assumption here that requiring signed AuthnRequests can be done on an SP-by-SP basis. Is SP-by-SP control possible? 

It appears that requiring AuthnRequest signing would be done in relying-party.xml in the SecurityPolicy section for the relevant protocol (e.g., shibboleth.SAML2SSOSecurityPolicy) by adding the appropriate rule (security:MandatoryMessageAuthentication?) But those rules look fairly global to the RelyingPartyGroup element, and not clearly scopeable to individual RPs or ProfileConfigurations.

--- Eric





More information about the users mailing list