SP 3.4.1 and request signing

Brent Putman putmanb at georgetown.edu
Sat Sep 16 17:32:10 UTC 2023


On 9/16/23 1:00 PM, Wessel, Keith via users wrote:
>
> 2023-09-16 11:40:35 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [1] [default]: signing the message
> 2023-09-16 11:40:35 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [1] [default]: message encoded, sending redirect to client


Remember that with the Redirect binding, the signature will not be an 
XML signature of the SAML AuthnRequest message, but rather a 
binding-level signature represented by query parameters on the redirect 
URL. Specifically you will expect to see query params Signature and SigAlg.

I don't know if that is the issue here, but it's the first thing it 
occurs to ask.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20230916/ab8423f0/attachment.htm>


More information about the users mailing list