disabling request signature validation?

IAM David Bantz dabantz at alaska.edu
Thu Apr 24 01:54:12 UTC 2025


A few SPs digitally sign requests, but rotate their signing certificate
frequently (and not always even just because they expire!). I've long
accommodated them but am now considering the sage advice I've been given to
disable validation of signed requests for (at least some of) these SPs.

I can remove the AuthnRequestsSigned="true" element and signing certificate
from our local cache of the SP metadata of course, but what will the IdP
(5.4.2) do with a signed request that cannot be validated? Do I also need a
relying-party override to ignore the fact that the signature on the request
cannot be validated?

David St PIerre Bantz
U Alaska IAM
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20250423/d6c6ecf0/attachment.htm>


More information about the users mailing list