what controls assertion signing?
Mark K. Miller
max at psu.edu
Thu Feb 5 19:36:51 EST 2015
On Fri, 6 Feb 2015, Peter Schober wrote:
> * Mark K. Miller <max at psu.edu> [2015-02-06 01:01]:
>> If metadata for an SP has WantAssertionsSigned="true" in it, but the
>> profile in the relying party config on the IdP has signAssertions="never"
>> should assertions from that IdP to that SP be signed, or not?
>
> If IDP config doesn't trump what others put into metadata
Ok, we're on the same page here.
> you shoulf
> file a bug, IMO.
I'd have to try it with some newer software first.
>> And, for my InCommon Federation friends (yes, I realize this list is more
>> general than that) is there a way to have InCommon metadata include
>> WantAssertionsSigned="true" for an SP's metadata?
>
> See Scott's comment from today or yesterday about how signing the
> Response instead is recommended today.
Yes, this was already bothering me then, and I did pay very close
attention to Scott's comments reenforcing what I thought I knew.
> So you should start explaining
> (not to me, necessarily) why you'd want that.
Peter, you take the time to answer, the least I can do is explain to you! ;-)
I don't want it; a vendor I'm dealing with thinks they do. :-(
> -peter
Thank you!
Max
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list