Can encryptAssertions be configured for a specific SP
Kevin Foote
kpfoote at uoregon.edu
Thu Jan 8 13:32:30 EST 2015
> On Jan 8, 2015, at 10:28 AM, Jeffrey McKenzie <JMcKenzie at trustwave.com> wrote:
>
> I can see how to turn off encrypting assertions for the Shibboleth IDP by setting the ProfileConfiguration encryptAssertions in the relying-party.xml to "never". But that means it'll never encryptAssertions for anyone, right? Can I configure the IDP to only encryptAssertions to specific Service Providers.
>
> Or more precisely what I'd like to do it turn encryption of assertions off for a particular service provider that can't seem to handle pulling my login id out of an attribute in the assertion AND decrypting the assertion. However for other service providers I'd like to be able to leave encryption of assertions set to "conditional”.
Yes you can do this on a per RP basis within the relying-party.xml
What you set was probably the default which is the catch all configuration.
You can also check back in the list archives - This same thread came up late Nov or early Dec :-)
--------
thanks
kevin.foote
More information about the users
mailing list