SAML2ECPProfile problems

Peter Schober peter.schober at univie.ac.at
Mon Mar 17 16:57:10 EDT 2014


* Michael Dahlberg <dahlberg at bucknell.edu> [2014-03-17 19:49]:
>    To turn off assertion encryption, open the
>    SHIBBOLETH_HOME/conf/relying-party.xml file and within the
>    <DefaultRelyingParty>"saml: SAML2SSOProfile" section, change the value
>    of encryptAssertions to never.

Also (once you upgrade your IDP) I would not turn off encryption for
all SPs only to deal with one SP's brokenness. Instead, add a custom
RelyingParty element for that SP as per the documentation.
-peter


More information about the users mailing list