Can encryptAssertions be configured for a specific SP
Jeffrey McKenzie
JMcKenzie at trustwave.com
Thu Jan 8 13:28:13 EST 2015
I can see how to turn off encrypting assertions for the Shibboleth IDP by setting the ProfileConfiguration encryptAssertions in the relying-party.xml to "never". But that means it'll never encryptAssertions for anyone, right? Can I configure the IDP to only encryptAssertions to specific Service Providers.
Or more precisely what I'd like to do it turn encryption of assertions off for a particular service provider that can't seem to handle pulling my login id out of an attribute in the assertion AND decrypting the assertion. However for other service providers I'd like to be able to leave encryption of assertions set to "conditional".
________________________________
This transmission may contain information that is privileged, confidential, and/or exempt from disclosure under applicable law. If you are not the intended recipient, you are hereby notified that any disclosure, copying, distribution, or use of the information contained herein (including any reliance thereon) is strictly prohibited. If you received this transmission in error, please immediately contact the sender and destroy the material in its entirety, whether in electronic or hard copy format.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20150108/f071d614/attachment.html
More information about the users
mailing list