Auth Request not signed
Brent Putman
putmanb at georgetown.edu
Tue Dec 5 20:38:34 UTC 2023
On 12/5/23 3:12 PM, Cantor, Scott via users wrote:
>> This is what I have right now
> Then it would be signing, so I'm gonna go with "it's signed and whoever is telling you it's not is wrong".
And to add to what Scott says, because this comes up occasionally:
Remember that with an AuthnRequest (or other SAML 2 SSO request), there
can be 2 types of signatures based on the binding: 1) the Redirect
binding will have a binding-level signature represented as query params
2) the POST binding will have an XML signature of the AuthnRequest
itself. Sometimes people forget about type #1, and are only looking
for type #2.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20231205/be027eb5/attachment.htm>
More information about the users
mailing list