Shibboleth won't sign assertions?

Jeremy Morton jez9999 at gmail.com
Wed Feb 4 12:34:48 EST 2015


On Wed, Feb 4, 2015 at 4:48 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:

> > As far as I can tell, SAML2 says that the "Issuer" is only mandatory
> inside the
> > assertion element (inside the response, it's optional), and as that's
> what we
> > need to be able to trust, surely it's the assertion that it's important
> be
> > signed?
>
> The assertion has to be protected, which can be done a number of different
> ways. Issuer is only optional in a response if it's not signed.
>

saml-core-2.0-os-4.pdf, line 1566:
  <saml:Issuer> [Optional]
  Identifies the entity that generated the response message. (For more
information on this element, see
  Section 2.2.5.)

I don't see anything in the above spec about it ever being a non-optional
element.

Best regards,
Jeremy Morton (Jez)
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20150204/78745c89/attachment.html 


More information about the users mailing list