Define a relying party profile for AuthnRequestsSigned="true"
Karla Borecky
kborecky at smith.edu
Thu Feb 25 13:30:28 EST 2016
Oh, so the thing in the SP's metadata is saying *it* will be signing
requests. Sorry - I was confused because it's right in the same place
as WantAssertionsSigned="true" - but I suppose I should pay attention to
the difference: '*want *assertions signed' indicating something it expects
from the IdP. I see those all have "want..." in them. Duh.
Thank you!
Now to tackle their desire to have a NameIDFormat of "unspecified." :-P
On Thu, Feb 25, 2016 at 11:46 AM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> > I see that the default for all SAML profiles is
> >
> > signedRequestsPredicate = alwaysFalse
> >
> > I don't know if this is the setting that corresponds to the SP's
> > "AuthnRequests" one - so that's my first question.
>
> It's not related at all. Peter answered the rest. I actually had thought
> we didn't even look at the flag, but there is a policy rule that should be
> enforcing it.
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
--
Karla Borecky
Systems Administrator
ITS
Smith College
Northampton, MA 01063
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160225/22d6e7e1/attachment.html>
More information about the users
mailing list