Can encryptAssertions be configured for a specific SP
Lohr, Donald
lohrda at jmu.edu
Tue Mar 24 10:29:05 EDT 2015
On 01/08/2015 01:32 PM, Kevin Foote wrote:
>> On Jan 8, 2015, at 10:28 AM, Jeffrey McKenzie <JMcKenzie at trustwave.com> wrote:
>>
>> I can see how to turn off encrypting assertions for the Shibboleth IDP by setting the ProfileConfiguration encryptAssertions in the relying-party.xml to "never". But that means it'll never encryptAssertions for anyone, right? Can I configure the IDP to only encryptAssertions to specific Service Providers.
>>
>> Or more precisely what I'd like to do it turn encryption of assertions off for a particular service provider that can't seem to handle pulling my login id out of an attribute in the assertion AND decrypting the assertion. However for other service providers I'd like to be able to leave encryption of assertions set to "conditional”.
> Yes you can do this on a per RP basis within the relying-party.xml
> What you set was probably the default which is the catch all configuration.
>
> You can also check back in the list archives - This same thread came up late Nov or early Dec :-)
>
> --------
> thanks
> kevin.foote
I've done some looking and searching, but can not readily find the
previous thread mentioned below. I would be interested in how to
accomplish this.
Thanks for the support you folks provide.
Don
--
D o n a l d L o h r
i n f o r m a t i o n s y s t e m s
j a m e s m a d i s o n u n i v e r s i t y
5 4 0 . 5 6 8 . 3 7 3 0
More information about the users
mailing list