Sending the SAMLReply/Assertion

Mak, Steve makst at upenn.edu
Tue Jul 13 13:16:53 UTC 2021


I've also tried to argue this with vendors that insist that we're using a "sha1 pub cert" simply because the cert signature algorithm is sha1, despite us using a sha256 digest/XML signature.

In the end we had to cut them a new pub cert with a "signature algorithm" that made them happy, sadly.

It's also not terribly hard to use a script to hit the idp-initiated endpoint to generate a signed saml response/assertion if the IdP supports it.

- Steve



More information about the users mailing list