what controls assertion signing?

Mark K. Miller max at psu.edu
Thu Feb 5 19:36:51 EST 2015


On Fri, 6 Feb 2015, Peter Schober wrote:

> * Mark K. Miller <max at psu.edu> [2015-02-06 01:01]:
>> If metadata for an SP has WantAssertionsSigned="true" in it, but the
>> profile in the relying party config on the IdP has signAssertions="never"
>> should assertions from that IdP to that SP be signed, or not?
>
> If IDP config doesn't trump what others put into metadata

Ok, we're on the same page here.

>                                                           you shoulf
> file a bug, IMO.

I'd have to try it with some newer software first.

>> And, for my InCommon Federation friends (yes, I realize this list is more
>> general than that) is there a way to have InCommon metadata include
>> WantAssertionsSigned="true" for an SP's metadata?
>
> See Scott's comment from today or yesterday about how signing the
> Response instead is recommended today.

Yes, this was already bothering me then, and I did pay very close 
attention to Scott's comments reenforcing what I thought I knew.

>                                        So you should start explaining
> (not to me, necessarily) why you'd want that.

Peter, you take the time to answer, the least I can do is explain to you! ;-)

I don't want it; a vendor I'm dealing with thinks they do.  :-(

> -peter

Thank you!

Max

> -- 
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list