SP 3.4.1 and request signing

Wessel, Keith kwessel at illinois.edu
Sat Sep 16 21:35:34 UTC 2023


I had totally forgotten that, Brent. I’m so used to seeing the signature in the body of the request itself for post bindings. Thank you. And in fact, I just tested on my sandbox, and skipEndpointValidation is functioning properly. The SP admin reported it wasn’tworking for him, and when I didn’t see the signature, I didn’t even bother testing it all the way through on my sandbox.

Thank you for the reminder.

Keith


From: Brent Putman <putmanb at georgetown.edu>
Sent: Saturday, September 16, 2023 12:32 PM
To: Shib Users <users at shibboleth.net>
Cc: Wessel, Keith <kwessel at illinois.edu>
Subject: Re: SP 3.4.1 and request signing



On 9/16/23 1:00 PM, Wessel, Keith via users wrote:





2023-09-16 11:40:35 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [1] [default]: signing the message

2023-09-16 11:40:35 DEBUG OpenSAML.MessageEncoder.SAML2Redirect [1] [default]: message encoded, sending redirect to client



Remember that with the Redirect binding, the signature will not be an XML signature of the SAML AuthnRequest message, but rather a binding-level signature represented by query parameters on the redirect URL. Specifically you will expect to see query params Signature and SigAlg.

I don't know if that is the issue here, but it's the first thing it occurs to ask.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20230916/cfd5891e/attachment.htm>


More information about the users mailing list