Can encryptAssertions be configured for a specific SP
Cantor, Scott
cantor.2 at osu.edu
Wed Apr 8 16:57:03 EDT 2015
On 4/8/15, 8:45 PM, "Lohr, Donald" <lohrda at jmu.edu> wrote:
>I'm not sure that I'm fully following the context of your reply.
I'm just saying that if you couldn't follow what to do from that page
alone (the "additional research" comment), we should try and fix that.
>The additional research was a quest to find a specific example like the
>one I included earlier in my "4/8/15, 2:18 PM" posting.
If you need an example, then the explanation of what the setting does
isn't good enough, so that's what I'm trying to fix. Not really for V2 per
se, but eventually when I enhance the V3 docs.
>Having said that, does the example in my earlier post look like a
>workable solution to set a specific SP to have encryptAssertions="never"
>and keep the DefaultRelyingParty at encryptAssertions="conditional" ?
Yes, but I can't always look at some XML and notice a small problem. The
answer is, you define an override element with a Name matching the SP, add
in whatever ProfileConfigurations you want to leave turned on for it, and
then include the non-default settings you want that profile to have. If
that's what you did, it's going to be right.
-- Scott
More information about the users
mailing list