Unknown or Unusable Identity Provider for Shib 3.2 SP

Cantor, Scott cantor.2 at osu.edu
Wed Jun 5 18:47:49 UTC 2024


> "SAML AuthnRequests that are signed will have their
> signature validated unless specifically disabled by setting
> validate.authnrequest to false . If unset (or set to true )
> signatures will be validated if present and requests not
> passing validation will be refused."

If that's a change, then the old IdP version had a serious bug but it would suggest that SP has been signing all along with no key in its metadata and the IdP was just ignoring it until now.

-- Scott




More information about the users mailing list