SP SLO responses not signed

Cantor, Scott cantor.2 at osu.edu
Tue Aug 13 14:17:56 UTC 2024


Signing is automatic in those cases if it's not disabled, as long as it has a key to sign with.

A redirect bound request is not signed inside the XML and it would not be visible there, you can trace the traffic yourself with a browser if you want to prove that.

> SAML requests from the SP are signed properly.

A logout request *is* a SAML request. If you mean an authentication request, those should NOT be signed. There is no reason to do that.

-- Scott




More information about the users mailing list