Signatures in v3 vs v2

Schwoerer, Brad schwoerb at uww.edu
Wed Jan 13 12:56:02 EST 2016


Thanks.  Sorry I missed the example at the bottom of https://wiki.shibboleth.net/confluence/display/IDP30/RelyingPartyConfiguration where the example shows exactly that.




On 1/12/16, 4:15 PM, "users on behalf of Cantor, Scott" <users-bounces at shibboleth.net on behalf of cantor.2 at osu.edu> wrote:

>> I was wondering if it is possible that I could change how the signatures work
>> for one of my SPs in v3.  I have made other changes for security settings and
>> alternate credentials in v3 relying party, but can't find a setting corresponding
>> to something like this
>
>signAssertions and signResponses are the controlling properties.
>
>Signing assertions is historical and avoided now when encryption is on because allowing unsigned encrypted data exposes an XML Encryption flaw, but unless SPs actually enforce that (and certainly nothing this broken would), it doesn't much matter what you do.
>
>-- Scott
>
>-- 
>To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list