Is it more common for SP or IdP to dictate if assertions should be encrypted?

Cody Carmichael ccarmichael at voalte.com
Tue Feb 12 17:17:40 EST 2019


I'm working with a client engineer who says that his IdP looks to the SP
metadata to see if assertions should be encrypted. I'm seeing some ways for
how to do this in the SP metadata like

<Attribute name="wantAssertionEncrypted">
> Value></Value>


 Or

WantAssertionsEncrypted="true"


 I don't know if one of these is more correct than the other. But is it
typical for SPs to drive this? Or is this more typically a configuration on
the IdP end?
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20190212/d4549487/attachment.html>


More information about the users mailing list