SP unsigned requests with AuthnRequestsSigned="true"
IAM David Bantz
dabantz at alaska.edu
Fri Jul 18 20:10:06 UTC 2025
A (new to us) SP provides metadata with a cert
and AuthnRequestsSigned="true", but is sending unsigned requests (clearly
stated in IdP logs, and verified using samlTracer). I've asserted the SP is
misbehaving and reset AuthnRequestsSigned="false" in our metadata cache
which enables successful SSO logins. But the vendor is not convinced -
alleging other institutions haven't encountered this issue. The service is
AbsenceSoft (https://absencesoft.com), and my question to the list is
whether you have successfully integrated the "Admin" portal of this service
and are receiving signed requests (implicating the SP configuration for our
instance). Or if you accommodate their unsigned requests by setting
AuthnRequestsSigned="false" (indicating a more general problem for the
vendor) or have an IdP config that tolerates their inconsistency (I hope
not). [As the IdP operator, I'm OK with the workaround of setting
AuthnRequestsSigned="false", particularly since they do consume encrypted
responses; but both SP and local service owner continue to pursue.]
David St PIerre Bantz
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20250718/3b626e7e/attachment.htm>
More information about the users
mailing list