<html><body><div style="color:#000; background-color:#fff; font-family:arial, helvetica, sans-serif;font-size:12pt"><div><span>I asked the client to test after I made the sign="true" setting but he says he is still not getting a signed authNRequest:</span></div><div><br><span></span></div><div class="MsoNormal" style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; background-color: rgb(255, 255, 255); "><span style="font-size: 11pt; color: rgb(31, 73, 125); ">I still do not see the signature in the AuthNRequest:</span></div><div class="MsoNormal"
style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; background-color: rgb(255, 255, 255); "><span style="font-size: 11pt; color: rgb(31, 73, 125); "> </span></div><div class="MsoNormal" style="margin: 0px; color: rgb(34, 34, 34); font-family: arial,sans-serif; font-size: 13px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; background-color: rgb(255, 255, 255);"><span style="font-size: 11pt;
color: rgb(31, 73, 125);"><samlp:AuthnRequest xmlns:samlp="urn:oasis:names:<wbr>tc:SAML:2.0:protocol" AssertionConsumerServiceURL="<a href="https://shib.lynda.com/Shibboleth.sso/SAML2/POST" target="_blank" style="color: rgb(53, 66, 88); ">h<wbr>ttps://shib.lynda.com/<wbr>Shibboleth.sso/SAML2/POST</a>" Destination="<a href="https://alliancetest.qualcomm.com/fed/idp/samlv20" target="_blank" style="color: rgb(53, 66, 88); ">https://<wbr>alliancetest.qualcomm.com/fed/<wbr>idp/samlv20</a>" ID="_<wbr>25673b8d16e076e3dc1caf2815a02a<wbr>3a" IssueInstant="2011-11-03T20:<wbr>02:51Z" ProtocolBinding="urn:oasis:<wbr>names:tc:SAML:2.0:bindings:<wbr>HTTP-POST" Version="2.0"><saml:Issuer xmlns:saml="urn:oasis:names:<wbr>tc:SAML:2.0:assertion"><a href="https://shib.lynda.com/shibboleth-sp" target="_blank" style="color: rgb(53, 66, 88); ">https:/<wbr>/shib.lynda.com/shibboleth-sp</a><<wbr>/saml:Issuer><samlp:<wbr>NameIDPolicy
AllowCreate="1"/></samlp:<wbr>AuthnRequest></span></div><div class="MsoNormal" style="margin: 0px; color: rgb(34, 34, 34); font-family: arial,sans-serif; font-size: 13px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; background-color: rgb(255, 255, 255);"><br><span style="font-size: 11pt; color: rgb(31, 73, 125);"></span></div><div class="MsoNormal" style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto;
-webkit-text-stroke-width: 0px; background-color: rgb(255, 255, 255); "><span style="font-size: 11pt; color: rgb(31, 73, 125); ">Any thoughts?<br></span></div><div><br></div><div style="font-family: arial, helvetica, sans-serif; font-size: 12pt;"><div style="font-family: times new roman, new york, times, serif; font-size: 12pt;"><font size="2" face="Arial"><hr size="1"><b><span style="font-weight:bold;">From:</span></b> Mark K. Miller <max@psu.edu><br><b><span style="font-weight: bold;">To:</span></b> Shib Users <users@shibboleth.net><br><b><span style="font-weight: bold;">Sent:</span></b> Thursday, November 3, 2011 12:37 PM<br><b><span style="font-weight: bold;">Subject:</span></b> Re: authn request signing<br></font><br>
<br>Mike and I just finished testing again; it works now. Scott was <br>absolutely correct about the metadata.<br><br>Thanks for your help, Scott!<br><br>On Thu, 3 Nov 2011, Mark K. Miller wrote:<br><br>> On Thu, 3 Nov 2011, Cantor, Scott wrote:<br>><br>>> On 11/3/11 11:26 AM, "Mike Flynn" <<a ymailto="mailto:shibbolethlynda@yahoo.com" href="mailto:shibbolethlynda@yahoo.com">shibbolethlynda@yahoo.com</a>> wrote:<br>>>><br>>>> And then<br>>>> did a test with Max at PSU. It failed.<br>>><br>>> If it failed, then I would imagine your metadata must be wrong. The only<br>>> reason it should fail is if your signature wasn't trusted.<br>><br>> I imagine that you imagine correctly (as always.)<br>><br>> I feel real silly that I didn't realize this. Especially, given that upon<br>> declaring the test a failure I went right off and updated my metadata<br>> because
Mike was up to the steps in the key rollover process where he had<br>> added another cert to the metadata.<br>><br>> In a separate note directly to Mike, I suggested we repeat the test and I<br>> expect it'll work now.<br>><br>> Thanks, Scott!<br>><br>>>> Do I need to include the encryption setting and have it set to true along<br>>>> with signing="true"?<br>>><br>>> There is nothing in the request that's encrypted, the setting won't matter.<br>>><br>>>> If these values are not present in the ApplicationDefaults, I presume<br>>>> that Shibboleth defaults them both to false - correct?<br>>><br>>> Yes; you can find that out in the documentation. I documented every<br>>> setting.<br>>><br>>>> Is this customer wrong when they indicate that authn request signing will<br>>>> have no impact on existing Idps? I assume they are since PSU's
shib<br>>>> connection attempt failed. Or, would setting both encryption and signing<br>>>> on applicationdefaults have prevented the error?<br>>><br>>> No, and any time the metadata is wrong, virtually anything can fail.<br>>><br>>> You can also override the setting for the specific relying party, as<br>>> documented.<br>>><br>>> -- Scott<br>>><br>>> --<br>>> To unsubscribe from this list send an email to <a ymailto="mailto:users-unsubscribe@shibboleth.net" href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>> --<br>> To unsubscribe from this list send an email to <a ymailto="mailto:users-unsubscribe@shibboleth.net" href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>><br>--<br>To unsubscribe from this list send an email to <a ymailto="mailto:users-unsubscribe@shibboleth.net"
href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br><br><br></div></div></div></body></html>