encrypted assertions

Cantor, Scott cantor.2 at osu.edu
Tue Aug 19 15:38:52 EDT 2014


On 8/19/14, 3:03 PM, "Chris Phillips" <Chris.Phillips at canarie.ca> wrote:

>From my perspective, it's a specific implementation profile on the SAML2
>spec, it's there to be used but not required to be 'enabled' (or is it?)
>others may have more insight.

It's required to implement, but not to enable.

>For instance, ADFS supports SAML2 but sending it an encrypted assertion
>gives it grief (at least my instance).

They handle it, AFAIK.

>(yes, my signing key is separate from my encryption key -- still borks and
>event viewer is oh so helpful *cough*.
>If anyone has this clearly sorted out I'd love to hear from you).

When I've tested against ADFS, I've done it with encryption on.

-- Scott



More information about the users mailing list