what controls assertion signing?

Peter Schober peter.schober at univie.ac.at
Thu Feb 5 19:04:33 EST 2015


* Mark K. Miller <max at psu.edu> [2015-02-06 01:01]:
> If metadata for an SP has WantAssertionsSigned="true" in it, but the 
> profile in the relying party config on the IdP has signAssertions="never" 
> should assertions from that IdP to that SP be signed, or not?

If IDP config doesn't trump what others put into metadata you shoulf
file a bug, IMO.

> And, for my InCommon Federation friends (yes, I realize this list is more 
> general than that) is there a way to have InCommon metadata include 
> WantAssertionsSigned="true" for an SP's metadata?

See Scott's comment from today or yesterday about how signing the
Response instead is recommended today. So you should start explaining
(not to me, necessarily) why you'd want that.
-peter


More information about the users mailing list