encryptAssertions="conditional"

Liam Hoekenga liamr at umich.edu
Wed Nov 12 12:00:21 EST 2014


Hey folks -

Our default settings for the SAML2SSOProfile includes
 "encryptAssertions="conditional"".

We've got an SP that we don't have a cert for that we're (unsurprisingly)
getting an encryption error on..

   <saml2p:Status>
      <saml2p:StatusCode
Value="urn:oasis:names:tc:SAML:2.0:status:Responder"/>
      <saml2p:StatusMessage>Unable to encrypt
assertion</saml2p:StatusMessage>
   </saml2p:Status>

What I can't figure out is why it's decided it should encrypt the
assertion?  I've checked the metadata and looked at the incoming request...

Liam
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20141112/9dd0477f/attachment.html 


More information about the users mailing list