Shibboleth as SAML Proxy

Mak, Steve makst at upenn.edu
Fri Jul 9 14:40:54 UTC 2021


The only exception I can really justify is for a wildcard-ACS enabled SP, but hardly anyone uses those.

On 7/6/21, 3:08 PM, "users on behalf of Cantor, Scott" <users-bounces at shibboleth.net on behalf of cantor.2 at osu.edu> wrote:

    There's no reason anybody should ever sign a SAML AuthnRequest.

    The signRequests profile option on the SAML.SSO profile bean is what controls it.

    You should not do it, that's wasted CPU time for all concerned.

    -- Scott


    -- 
    For Consortium Member technical support, see https://wiki.shibboleth.net/confluence/x/coFAAg
    To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net



More information about the users mailing list