Shibboleth IDP version 4.1.2 not honoring wantAuthnRequestsSigned Flag
Kumar, Prasanth (ELS-LON)
p.kumar.13 at elsevier.com
Fri Jul 9 09:06:09 UTC 2021
When shibboleth service provider sends an non-signed authn requests then identify provider should be rejecting the request in this case.
Please see our configuration changes below
On metadata this flag set to false - <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol" WantAuthnRequestsSigned="false">
Following https://wiki.shibboleth.net/confluence/display/IDP4/SAML2SSOConfiguration configuration changes on IDP side doesn't seems to working:
idp.saml.honorWantAuthnRequestsSigned=true in idp.properties file
Do I have to enable the flag in <SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol" AuthnRequestsSigned="false">
Thanks in advance,
Prasanth
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20210709/897f33e8/attachment.htm>
More information about the users
mailing list