Is it more common for SP or IdP to dictate if assertions should be encrypted?

Cantor, Scott cantor.2 at osu.edu
Tue Feb 12 17:25:54 EST 2019


 >  I don't know if one of these is more correct than the other. But is it typical for
> SPs to drive this? Or is this more typically a configuration on the IdP end?

The standard, and the profile in question that's relevant to the question, required support for encryption and it should always be done (but is almost never done with an algorithm that's actually secure, a separate problem).

If an SP implementation is non-compliant or a deployer is lazy and doesn't support encryption, the only signal necessary for that is having no encryption key to use, and IdPs have to make their own decisions what to support and when.

-- Scott



More information about the users mailing list