SP unsigned requests with AuthnRequestsSigned="true"
Cantor, Scott
cantor.2 at osu.edu
Fri Jul 18 21:47:28 UTC 2025
When various folks tell me the standard is "vague" and I react somewhat aggressively, this is why.
Quoting:
"However, an identity provider that receives an unsigned <samlp:AuthnRequest> message from a service provider whose metadata contains this attribute with a value of true MUST return a SAML error response and MUST NOT fulfill the request."
Is that somehow unclear?
-- Scott
More information about the users
mailing list