AuthnRequestsSigned="true"
Cantor, Scott
cantor.2 at osu.edu
Fri Feb 10 16:13:00 EST 2017
On 2/10/17, 4:02 PM, "users on behalf of Tom Poage" <users-bounces at shibboleth.net on behalf of tfpoage at ucdavis.edu> wrote:
> The AuthnRequest ended up not containing a signature, but the IdP went ahead and sent an Assertion with complete
> Subject and AttributeStatement.
If it did, then the request was in fact signed, and you're probably confused about the fact that signed redirects don't show up as a signature inside the message, and you're looking at the log trace.
If not, I suppose a regression could have occurred, but I doubt it.
-- Scott
More information about the users
mailing list