assertion not always signed

Tom Poage tfpoage at ucdavis.edu
Mon Jan 16 11:28:55 EST 2017


> On Jan 13, 2017, at 5:06 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> 
> On 1/13/17, 7:53 PM, "users on behalf of Tom Poage" <users-bounces at shibboleth.net on behalf of tfpoage at ucdavis.edu> wrote:
> 
>> Here's the original observation sent our way on the issue. IdP-initiated SSO. About a two-minute gap between logins (no
>> IdP changes). Sorry, they're not complete assertions, cf. saml2p:Status.
> 
> You said no signature at all. I'm simply saying there will always be at least a response signature if it's set to do that, regardless of what triggers or doesn't trigger assertion signing.

Found log entries (text file attached, if this list allows). Two IdP-initiated requests, nine seconds apart ("===..." separation). Same v3.2.1 IdP. Same user, same browser. The first response has signature, the second none.

This alone is likely reason enough to update to 3.3.

Tom.
-------------- next part --------------
An embedded and charset-unspecified text was scrubbed...
Name: saml-trace.txt
URL: <http://shibboleth.net/pipermail/users/attachments/20170116/bc56d232/attachment-0001.txt>


More information about the users mailing list