Getting Signed SAML assertion in application

Peter Schober peter.schober at univie.ac.at
Mon Jan 20 08:32:17 EST 2014


* Peter Schober <peter.schober at univie.ac.at> [2014-01-20 13:44]:
> * Peter Schober <peter.schober at univie.ac.at> [2014-01-20 13:38]:
> > * Stefan Rasmusson <rasmusson.stefan at gmail.com> [2014-01-20 13:31]:
> > > In our application we have the need to get the entire signed SAML
> > > assertion. Because of security reasons our backend does not trust the
> > > frontend or shiboleth SP and must be able to verify the IDP signature.
> > > Is it possible to get the Assertion from the application some how?
> > 
> > https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPAssertionExport
> 
> That won't help with those "security reasons, though, as that does not
> expose the "raw" assertion as recieved (I think).

Or it just might. Reading the warning section more closely it says
"the XML is passed along unmodified from the issuer".
I agree with Leif about the justification to do that, of course.
-peter


More information about the users mailing list