AuthnRequestsSigned="true"

Cantor, Scott cantor.2 at osu.edu
Fri Feb 10 16:13:00 EST 2017


On 2/10/17, 4:02 PM, "users on behalf of Tom Poage" <users-bounces at shibboleth.net on behalf of tfpoage at ucdavis.edu> wrote:

> The AuthnRequest ended up not containing a signature, but the IdP went ahead and sent an Assertion with complete
> Subject and AttributeStatement.

If it did, then the request was in fact signed, and you're probably confused about the fact that signed redirects don't show up as a signature inside the message, and you're looking at the log trace.
    
If not, I suppose a regression could have occurred, but I doubt it.

-- Scott
    



More information about the users mailing list