Sending the SAMLReply/Assertion
Mak, Steve
makst at upenn.edu
Tue Jul 13 13:16:53 UTC 2021
I've also tried to argue this with vendors that insist that we're using a "sha1 pub cert" simply because the cert signature algorithm is sha1, despite us using a sha256 digest/XML signature.
In the end we had to cut them a new pub cert with a "signature algorithm" that made them happy, sadly.
It's also not terribly hard to use a script to hit the idp-initiated endpoint to generate a signed saml response/assertion if the IdP supports it.
- Steve
More information about the users
mailing list