Auth Request not signed

Brent Putman putmanb at georgetown.edu
Tue Dec 5 20:38:34 UTC 2023


On 12/5/23 3:12 PM, Cantor, Scott via users wrote:
>> This is what I have right now
> Then it would be signing, so I'm gonna go with "it's signed and whoever is telling you it's not is wrong".


And to add to what Scott says, because this comes up occasionally: 
Remember that with an AuthnRequest (or other SAML 2 SSO request), there 
can be 2 types of signatures based on the binding: 1) the Redirect 
binding will have a binding-level signature represented as query params 
2) the POST binding will have an XML signature of the AuthnRequest 
itself.  Sometimes people forget about type #1, and are only looking 
for type #2.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20231205/be027eb5/attachment.htm>


More information about the users mailing list