Shibboleth as SAML Proxy
Mak, Steve
makst at upenn.edu
Fri Jul 9 14:40:54 UTC 2021
The only exception I can really justify is for a wildcard-ACS enabled SP, but hardly anyone uses those.
On 7/6/21, 3:08 PM, "users on behalf of Cantor, Scott" <users-bounces at shibboleth.net on behalf of cantor.2 at osu.edu> wrote:
There's no reason anybody should ever sign a SAML AuthnRequest.
The signRequests profile option on the SAML.SSO profile bean is what controls it.
You should not do it, that's wasted CPU time for all concerned.
-- Scott
--
For Consortium Member technical support, see https://wiki.shibboleth.net/confluence/x/coFAAg
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list