disabling request signature validation?

Peter Schober peter.schober at univie.ac.at
Thu Apr 24 09:10:06 UTC 2025


IAM David Bantz via users <users at shibboleth.net> [2025-04-24 03:55 CEST]:
> I can remove the AuthnRequestsSigned="true" element

That's for letting the IDP fail the request if it's *not* signed, so
not your issue.

> what will the IdP (5.4.2) do with a signed request that cannot be
> validated?

Fail it, as mandated by the spec, IIRC.

-peter


More information about the users mailing list