Ex: endpoint security handler error

IAM David Bantz dabantz at alaska.edu
Wed Apr 24 01:14:54 UTC 2024


 Thank you Scott and Paul!

The request was signed (though their metadata has AuthnRequestsSigned=
“false”)

David

On Apr 23, 2024 at 16:49:26, Paul B. Henson <henson at cpp.edu> wrote:

> Is the authn request signed? Per the spec for POST,
>
> "If the message is signed, the Destination XML attribute in the root SAML
> element of the protocol message MUST contain the URL to which the sender
> has
> instructed the user agent to deliver the message."
>

On Apr 23, 2024 at 16:39:12, "Cantor, Scott" <cantor.2 at osu.edu> wrote:

What is wrong with that request+metadata combination ?

No Destination attribute. I thought we only enforced the requirement for
signed messages, but not sure.

— Scott
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20240423/9828f110/attachment.htm>


More information about the users mailing list