Signing authN requests: yea or nay?

Nate Klingenstein ndk at internet2.edu
Mon Sep 23 19:02:55 EDT 2013


I forgot to add that if you have a signed-AuthnRequest-only policy in place you will inevitably run into vendors and implementations that either can't figure out how to sign an AuthnRequest or are unwilling/unable to issue AuthnRequests at all anyway.  It will significantly reduce the pool of services that your IdP will be able to work with.


More information about the users mailing list