Avoiding signed requests verification by shibboleth IDP

kotesh201 koteshwarv at gmail.com
Thu Sep 5 14:10:09 EDT 2013


Hi Scott,

If I keep the certificates in metadata of SPs and have the TrustEngine
defined for those certificates in IDP, it is working fine. 
But in my scenario, I don't have control on Service provider configurations
and I would like to turn off IDP to verify any signed requests signature
permanently. I have my own handler to verify the signature, digest algorithm
check and certificate revocation etc.
Can I add/modify/delete anything in relying-party.xml or any other
configuration file which can skip verifying the signature. 

If you need any specific information from my configuration, I can provide it
to you.

Thanks in advance for your help.
-Kotesh



--
View this message in context: http://shibboleth.1660669.n2.nabble.com/Avoiding-signed-requests-verification-by-shibboleth-IDP-tp7589689p7589767.html
Sent from the Shibboleth - Users mailing list archive at Nabble.com.


More information about the users mailing list