AuthnRequestsSigned="true"

Tom Poage tfpoage at ucdavis.edu
Fri Feb 10 16:02:57 EST 2017


IdP 3.3.0

Integrating an SP with AuthnRequestsSigned="true" in their metadata.

The AuthnRequest ended up not containing a signature, but the IdP went ahead and sent an Assertion with complete Subject and AttributeStatement.

I recall if AuthnRequest is not signed, IdP either throws an error or returns an error SAML response (don't remember which).

The only 'core' change made recently in our end since upgrading to 3.3 is in idp.properties:

idp.encryption.optional = true

I didn't think this applied.

Or does it?

(bumping to debug to see if that reveals anything)
Tom.


More information about the users mailing list