SAML2 idp response

samir el otmani elotmani.samir at gmail.com
Wed Dec 10 13:15:28 EST 2014


thank you David, it works now

2014-12-10 17:46 GMT+00:00 IAM David Bantz <dabantz at alaska.edu>:

> You can view the assertion just prior to encryption in the IdP logs:
>
> DEBUG
> [edu.internet2.middleware.shibboleth.idp.profile.saml2.AbstractSAML2ProfileHandler:279]
> - Assertion to be encrypted is:
>
> ...
>
> <!-- To get the SAML assertion in the idp-process log, include this logger in
> logging.xml:
>
>      with level at DEBUG  -->
>
>     <logger
> name="edu.internet2.middleware.shibboleth.idp.profile.saml2.AbstractSAML2ProfileHandler">
>
>         <level value="DEBUG" />
>
>     </logger>
>
> David Bantz
>
> UAlaska IAM
>
> On Wed, Dec 10, 2014 at 8:09 AM, samir el otmani <elotmani.samir at gmail.com
> > wrote:
>
>> Hi all ,
>>
>> I want to display the SAML2 response from an IDP for debugging purpose ,
>> i think the IDP encode all attributes, i use SAML tracer in firefox , and
>> it shows a encrypted tags in SAML which is normal because idp encrypt it ,
>> so how can i see a pure SAML2 response before encryption .
>> other question : is it normal  if an  IDP sends a non encrypted SAML2
>> response; in another words is there any configuration in idp which indicate
>> that the SAML2 attributes will not be encrypted .
>>
>> thank you
>> --
>> *EL OTMANI Samir*
>> *Ingénieur d'Etat en Génie Informatique *
>> *Tel:+212 699 041 864*
>>
>> --
>> To unsubscribe from this list send an email to
>> users-unsubscribe at shibboleth.net
>>
>
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>



-- 
*EL OTMANI Samir*
*Ingénieur d'Etat en Génie Informatique *
*Tel:+212 699 041 864*
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20141210/33faf031/attachment.html 


More information about the users mailing list