Can encryptAssertions be configured for a specific SP

Cantor, Scott cantor.2 at osu.edu
Wed Apr 8 16:57:03 EDT 2015


On 4/8/15, 8:45 PM, "Lohr, Donald" <lohrda at jmu.edu> wrote:



>I'm not sure that I'm fully following the context of your reply.

I'm just saying that if you couldn't follow what to do from that page 
alone (the "additional research" comment), we should try and fix that.

>The additional research was a quest to find a specific example like the
>one I included earlier in my "4/8/15, 2:18 PM" posting.

If you need an example, then the explanation of what the setting does 
isn't good enough, so that's what I'm trying to fix. Not really for V2 per 
se, but eventually when I enhance the V3 docs.

>Having said that, does the example in my earlier post look like a
>workable solution to set a specific SP to have encryptAssertions="never" 
>and keep the DefaultRelyingParty at encryptAssertions="conditional" ?

Yes, but I can't always look at some XML and notice a small problem. The 
answer is, you define an override element with a Name matching the SP, add 
in whatever ProfileConfigurations you want to leave turned on for it, and 
then include the non-default settings you want that profile to have. If 
that's what you did, it's going to be right.

-- Scott



More information about the users mailing list