Shibboleth IdP v3 + Require signed Authnrequests

Cantor, Scott cantor.2 at osu.edu
Tue Jun 30 09:40:59 EDT 2015


On 6/30/15, 9:14 AM, "users on behalf of Keijo Korte" <users-bounces at shibboleth.net on behalf of keijo.korte at kvak.net> wrote:
>
>Is it possible to force IdPv3 to require signed authn requests? Of source this can be done via metadata with "AuthnRequestsSigned=true”, but I want to make sure that if that part is missing in metadata the IdP still requires that requests are signed.
>
>This was relative easy on version 2.x, but in version 3 I can’t find the working combination (relying-party.xml).

I'm not sure I recall any way to do that for 2.x, actually. I was going to say the answer was no, but if there was a way to do it before there probably is now. I can't think of any way off the top of my head except by manipulating security policy handlers, so I doubt there's any simple way now.

As I have covered several times, and though some disagree, my opinion is that you cannot do this while still supporting unsolicted responses either.

Why do you think you need to do this in the first place?

-- Scott



More information about the users mailing list