Unknown or Unusable Identity Provider for Shib 3.2 SP
Cantor, Scott
cantor.2 at osu.edu
Wed Jun 5 18:47:49 UTC 2024
> "SAML AuthnRequests that are signed will have their
> signature validated unless specifically disabled by setting
> validate.authnrequest to false . If unset (or set to true )
> signatures will be validated if present and requests not
> passing validation will be refused."
If that's a change, then the old IdP version had a serious bug but it would suggest that SP has been signing all along with no key in its metadata and the IdP was just ignoring it until now.
-- Scott
More information about the users
mailing list