How to specify signing responses?
Marc Boorshtein
mboorshtein at gmail.com
Wed Mar 11 12:54:00 EDT 2015
Thanks Scott, that was really helpful in getting me along the right path.
I've worked out how to update the relying-parties.xml file and add the
metadata extensions so I'm on my way. And you are completely correct.
Turned out that the problem existed between my keyboard and chair. I
needed the opposite (assertions signed, response open).
Thanks
Marc
On Wed, Mar 11, 2015 at 12:35 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> > > I feel like I'm missing something very obvious so sorry for the dumb
> > question.
> > > I can't figure out how to tell Shib IdP (v3) to sign the response to
> my SP
> > > instead of the assertion. Its not a standard part of the metadata so
> is there
> > > an extension or something i put into another config file?
> >
> >
> https://wiki.shibboleth.net/confluence/display/IDP30/SecurityConfiguration
>
> Also, the default in both SSO profiles is to sign the response, so you
> shouldn't have to do anything, actually.
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20150311/d215674d/attachment.html
More information about the users
mailing list