SP unsigned requests with AuthnRequestsSigned="true"

Cantor, Scott cantor.2 at osu.edu
Fri Jul 18 21:47:28 UTC 2025


When various folks tell me the standard is "vague" and I react somewhat aggressively, this is why.

Quoting:

"However, an identity provider that receives an unsigned <samlp:AuthnRequest> message from a service provider whose metadata contains this attribute with a value of true MUST return a SAML error response and MUST NOT fulfill the request."

Is that somehow unclear?

-- Scott




More information about the users mailing list