SAManage with Shibboleth 3?

Tom Scavo trscavo at gmail.com
Tue Apr 17 08:15:15 EDT 2018


On Tue, Apr 17, 2018 at 4:32 AM, Mark Cairney <Mark.Cairney at ed.ac.uk> wrote:
>
> It's a bit unusual (although I can't think of any
> technical reason why it wouldn't be possible) to have only one party
> signing it's assertions and/or response though.

The IdP is the only party *issuing* assertions and responses. The SP
issues a request, specifically a SAML AuthnRequest.

> I can't see any signing being done:
>
> <samlp:AuthnRequest ...

You're right, the above request is not signed (which is typical). In
your case, if it was signed, we'd be worried since you don't possess a
trusted signing certificate for the SP.

Basically, the request is fine. That is not the problem.

Tom


More information about the users mailing list